PT-2020-5619 · Dojo+2 · Dojox+2

Published

2020-02-13

·

Updated

2025-06-16

·

CVE-2019-10785

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions dojox versions prior to 1.16.1 dojox versions prior to 1.15.2 dojox versions prior to 1.14.5 dojox versions prior to 1.13.6 dojox versions prior to 1.12.7 dojox versions prior to 1.11.9
Description The issue is related to the dojox.xmpp.util.xmlEncode function, which only encodes the first occurrence of each character, not all of them, leading to a potential Cross-site Scripting (XSS) vulnerability. This affects users of dojox/xmpp and dojox/dtl. The vulnerability may allow a remote attacker to impact the integrity of data.
Recommendations For dojox versions prior to 1.16.1, upgrade to version 1.16.1. For dojox versions prior to 1.15.2, upgrade to version 1.15.2. For dojox versions prior to 1.14.5, upgrade to version 1.14.5. For dojox versions prior to 1.13.6, upgrade to version 1.13.6. For dojox versions prior to 1.12.7, upgrade to version 1.12.7. For dojox versions prior to 1.11.9, upgrade to version 1.11.9. As a temporary workaround, the change applied in the patch could be added separately. Users of Dojo 1.10.x and earlier should review this change and determine if it impacts them, and backport the change as appropriate.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01281
CVE-2019-10785
DLA-2127-1
GHSA-PG97-WW7H-5MJR
MGASA-2020-0126
SNYK-JS-DOJOX-548257
USN-7569-1

Affected Products

Linuxmint
Ubuntu
Dojox