dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9. This is due to dojox.xmpp.util.xmlEncode only encoding the first occurrence of each character, not all of them.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: snyk
Published: 2020-02-13T16:02:46
Updated: 2024-08-04T22:32:01.603Z
Reserved: 2019-04-03T00:00:00
Link: CVE-2019-10785
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-02-13T17:15:29.477
Modified: 2024-11-21T04:19:55.027
Link: CVE-2019-10785
Redhat