VDB
Sign up
MEDIUM5.4

GHSA-p82g-2xpp-m5r3

Cross-Site Scripting in dojo

Quick fix

GHSA-p82g-2xpp-m5r3 — dojo: upgrade to the fixed version with the command below.

npm install dojo@1.9.1

Details

Versions of `dojo` prior to 1.2.0 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize HTML code in user-controlled input, allowing attackers to execute arbitrary JavaScript in the victim's browser.

## Recommendation

Upgrade to version 1.2.0 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/dojo
Introduced in: 0Fixed in: 1.9.1
Fixnpm install dojo@1.9.1

References