MEDIUM🇵🇱 Wersja polska

CVE-2018-6561

CVSS 6.1v3.0pub. 2018-02-02upd. 2024-11-21

dijit.Editor in Dojo Toolkit 1.13 allows XSS via the onload attribute of an SVG element.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  • Dojotoolkit Dojo

    APP
    Dojotoolkit
    1.13.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2018-15494CRITICAL9.8PL ✓same product

Dojo Toolkit: niezabezpieczone wstrzykiwanie ciągów w DataGrid

CVE-2010-2276HIGH10.0same product

The default configuration of the build process in Dojo 0.4.x before 0.4.4, 1.0.x before 1.0.3, 1.1.x before 1....

CVE-2010-2272HIGH10.0same product

Unspecified vulnerability in iframe_history.html in Dojo 0.4.x before 0.4.4 has unknown impact and remote atta...

CVE-2018-1000665MEDIUM6.1same product

Dojo Dojo Objective Harness (DOH) version prior to version 1.14 contains a Cross Site Scripting (XSS) vulnerab...

CVE-2015-5654MEDIUM4.3same product

Cross-site scripting (XSS) vulnerability in Dojo Toolkit before 1.2 allows remote attackers to inject arbitrar...