Affected versions of dojo
are susceptible to a cross-site scripting vulnerability in the dijit.Editor
and textarea
components, which execute their contents as Javascript, even when sanitized.
Update to version 1.1.0 or later.
{ "github_reviewed_at": "2020-08-31T18:11:03Z", "cwe_ids": [ "CWE-79" ], "nvd_published_at": null, "severity": "MODERATE", "github_reviewed": true }