VDB
Sign up
MEDIUM6.1

GHSA-wp32-wq34-2rqh

dijit editor cross-site scripting vulnerability

Quick fix

GHSA-wp32-wq34-2rqh — dijit: upgrade to the fixed version with the command below.

npm install dijit@1.13.1

Details

dijit.Editor in Dojo Toolkit 1.13 allows XSS via the onload attribute of an SVG element.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/dijit
Introduced in: 0Fixed in: 1.13.1
Fixnpm install dijit@1.13.1

References