← Zuruck zu CVEs
CVE-2019-10785
MEDIUM6.1
Beschreibung
dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9. This is due to dojox.xmpp.util.xmlEncode only encoding the first occurrence of each character, not all of them.
CVE Details
CVSS v3.1 Bewertung6.1
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionREQUIRED
Veroffentlicht2/13/2020
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
debian:debian_linuxlinuxfoundation:dojox
Schwachen (CWE)
CWE-79
Referenzen
https://snyk.io/vuln/SNYK-JS-DOJOX-548257%2C(report@snyk.io)
https://github.com/dojo/dojox/security/advisories/GHSA-pg97-ww7h-5mjr(af854a3a-2127-422b-91ae-364da2661108)
https://lists.debian.org/debian-lts-announce/2020/02/msg00033.html(af854a3a-2127-422b-91ae-364da2661108)
https://snyk.io/vuln/SNYK-JS-DOJOX-548257%2C(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.