CVE-2010-2273

EPSS 43.2%

Cross-Site Scripting in dojo

Published: 9/11/2019Modified: 11/8/2023
Also known as:GHSA-536q-8gxx-m782DEBIAN-CVE-2010-2273

Description

Versions of `dojo` prior to 1.4.2 are vulnerable to DOM-based Cross-Site Scripting (XSS). The package does not sanitize URL parameters in the `_testCommon.js` and `runner.html` test files, allowing attackers to execute arbitrary JavaScript in the victim's browser. ## Recommendation Upgrade to version 1.4.2 or later.

Affected packages (2)

References (20)