VDB
Sign up
LOW3.7

GHSA-cxjc-r2fp-7mq6

Cross-site Scripting in dijit editor's LinkDialog plugin

Quick fix

GHSA-cxjc-r2fp-7mq6 — dijit: upgrade to the fixed version with the command below.

npm install dijit@1.11.11

Details

### Impact XSS possible for users of the Dijit Editor's LinkDialog plugin

### Patches Yes, 1.11.11, 1.12.9, 1.13.8, 1.14.7, 1.15.4, 1.16.3

### Workarounds Users may apply the patch made in these releases.

### For more information If you have any questions or comments about this advisory, open an issue in [dojo/dijit](https://github.com/dojo/dijit/)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/dijit
Introduced in: 0Fixed in: 1.11.11
Fixnpm install dijit@1.11.11
npm/dijit
Introduced in: 1.12.0Fixed in: 1.12.9
Fixnpm install dijit@1.12.9
npm/dijit
Introduced in: 1.13.0Fixed in: 1.13.8
Fixnpm install dijit@1.13.8
npm/dijit
Introduced in: 1.14.0Fixed in: 1.14.7
Fixnpm install dijit@1.14.7
npm/dijit
Introduced in: 1.15.0Fixed in: 1.15.4
Fixnpm install dijit@1.15.4
npm/dijit
Introduced in: 1.16.0Fixed in: 1.16.3
Fixnpm install dijit@1.16.3

References