dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9. This is due to dojox.xmpp.util.xmlEncode only encoding the first occurrence of each character, not all of them.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2127-1 | dojo security update |
EUVD |
EUVD-2020-0309 | dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9. This is due to dojox.xmpp.util.xmlEncode only encoding the first occurrence of each character, not all of them. |
Github GHSA |
GHSA-pg97-ww7h-5mjr | XSS in dojox due to insufficient escape in dojox.xmpp.util.xmlEncode |
Ubuntu USN |
USN-7569-1 | Dojo vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-08-04T22:32:01.603Z
Reserved: 2019-04-03T00:00:00
Link: CVE-2019-10785
No data.
Status : Modified
Published: 2020-02-13T17:15:29.477
Modified: 2024-11-21T04:19:55.027
Link: CVE-2019-10785
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Github GHSA
Ubuntu USN