CVE-2019-10785

Description

dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9. This is due to dojox.xmpp.util.xmlEncode only encoding the first occurrence of each character, not all of them.

Risk Information

Base Score
6.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.243

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in IBM Security Guardium 10.5Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 10.6Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.1Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.2Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.3Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 20.0.0.1Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.0Windows
Modular JavaScript library (USN-7569-1) libjs-dojo-core_1.15.4+dfsg1-1ubuntu0.1_all.debLinux
Modular JavaScript library (USN-7569-1) libjs-dojo-dijit_1.15.4+dfsg1-1ubuntu0.1_all.debLinux
Modular JavaScript library (USN-7569-1) libjs-dojo-dojox_1.15.4+dfsg1-1ubuntu0.1_all.debLinux
Modular JavaScript library (USN-7569-1) shrinksafe_1.15.4+dfsg1-1ubuntu0.1_all.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234