dijit.Editor in Dojo Toolkit 1.13 allows XSS via the onload attribute of an SVG element.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NDojotoolkit Dojo
APPDojotoolkit1.13.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
Related vulnerabilities
CVE-2018-15494CRITICAL9.8PL ✓same product
Dojo Toolkit: niezabezpieczone wstrzykiwanie ciągów w DataGrid
CVE-2010-2276HIGH10.0same product
The default configuration of the build process in Dojo 0.4.x before 0.4.4, 1.0.x before 1.0.3, 1.1.x before 1....
CVE-2010-2272HIGH10.0same product
Unspecified vulnerability in iframe_history.html in Dojo 0.4.x before 0.4.4 has unknown impact and remote atta...
CVE-2018-1000665MEDIUM6.1same product
Dojo Dojo Objective Harness (DOH) version prior to version 1.14 contains a Cross Site Scripting (XSS) vulnerab...
CVE-2015-5654MEDIUM4.3same product
Cross-site scripting (XSS) vulnerability in Dojo Toolkit before 1.2 allows remote attackers to inject arbitrar...