Cross-site Scripting in dijit editor's LinkDialog plugin
Package
Affected versions
< 1.11.11
>= 1.12.0, < 1.12.9
>= 1.13.0, < 1.13.8
>= 1.14.0, < 1.14.7
>= 1.15.0, < 1.15.4
>= 1.16.0, < 1.16.3
Patched versions
1.11.11
1.12.9
1.13.8
1.14.7
1.15.4
1.16.3
Description
Reviewed
Jun 15, 2020
Published to the GitHub Advisory Database
Jun 15, 2020
Published by the National Vulnerability Database
Jun 15, 2020
Last updated
Mar 1, 2023
Impact
XSS possible for users of the Dijit Editor's LinkDialog plugin
Patches
Yes, 1.11.11, 1.12.9, 1.13.8, 1.14.7, 1.15.4, 1.16.3
Workarounds
Users may apply the patch made in these releases.
For more information
If you have any questions or comments about this advisory, open an issue in dojo/dijit
References