PT-2020-5619 · Dojo+2 · Dojox+2
Published
2020-02-13
·
Updated
2025-06-16
·
CVE-2019-10785
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
dojox versions prior to 1.16.1
dojox versions prior to 1.15.2
dojox versions prior to 1.14.5
dojox versions prior to 1.13.6
dojox versions prior to 1.12.7
dojox versions prior to 1.11.9
Description
The issue is related to the dojox.xmpp.util.xmlEncode function, which only encodes the first occurrence of each character, not all of them, leading to a potential Cross-site Scripting (XSS) vulnerability. This affects users of
dojox/xmpp and dojox/dtl. The vulnerability may allow a remote attacker to impact the integrity of data.Recommendations
For dojox versions prior to 1.16.1, upgrade to version 1.16.1.
For dojox versions prior to 1.15.2, upgrade to version 1.15.2.
For dojox versions prior to 1.14.5, upgrade to version 1.14.5.
For dojox versions prior to 1.13.6, upgrade to version 1.13.6.
For dojox versions prior to 1.12.7, upgrade to version 1.12.7.
For dojox versions prior to 1.11.9, upgrade to version 1.11.9.
As a temporary workaround, the change applied in the patch could be added separately. Users of Dojo 1.10.x and earlier should review this change and determine if it impacts them, and backport the change as appropriate.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Ubuntu
Dojox