CVE-2019-10785
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD
Description
dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9. This is due to dojox.xmpp.util.xmlEncode only encoding the first occurrence of each character, not all of them.
Affected (7)
Products: Linuxfoundation: Dojox · Debian: Debian Linux
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.11.0 to 1.11.9 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.0 |
References (6)
Source: report@snyk.io
ExploitThird Party Advisory
Source: report@snyk.io
Mailing ListThird Party Advisory
Source: report@snyk.io
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.