{"id":"GHSA-39cx-xcwj-3rc4","summary":"Cross-Site Scripting in dojo","details":"Affected versions of `dojo` are susceptible to a cross-site scripting vulnerability in the `dijit.Editor` and `textarea` components, which execute their contents as Javascript, even when sanitized.\n\n\n## Recommendation\n\nUpdate to version 1.1.0 or later.","aliases":["CVE-2008-6681"],"modified":"2023-11-08T03:56:52.043077Z","published":"2020-09-01T15:25:29Z","database_specific":{"github_reviewed_at":"2020-08-31T18:11:03Z","nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2008-6681"},{"type":"WEB","url":"https://bugs.dojotoolkit.org/ticket/2140"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/49883"},{"type":"WEB","url":"https://www.npmjs.com/advisories/107"},{"type":"WEB","url":"http://trac.dojotoolkit.org/changeset/15346"},{"type":"WEB","url":"http://trac.dojotoolkit.org/ticket/2140"},{"type":"WEB","url":"http://www.dojotoolkit.org/book/dojo-1-1-release-notes"},{"type":"WEB","url":"http://www.securityfocus.com/bid/34661"}],"affected":[{"package":{"name":"dojo","ecosystem":"npm","purl":"pkg:npm/dojo"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.1.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-39cx-xcwj-3rc4/GHSA-39cx-xcwj-3rc4.json"}}],"schema_version":"1.9.0"}