Junglewise Threat Intelligence

CVE-2010-2273: Dojo DOM-based cross-site scripting in test files

CVE-2010-2273 · Severity: info · CVSS 0 · Published 2019-09-11

Executive brief

Dojo is a widely-used JavaScript framework for building web applications. Versions prior to 1.4.2 contain a DOM-based cross-site scripting (XSS) vulnerability in test and documentation files that fail to sanitize URL parameters. An attacker can craft a malicious link that, when clicked by a developer or user, executes arbitrary JavaScript in the victim's browser, potentially leading to account compromise, data theft, or malware installation.

Technical details

The vulnerability is a DOM-based XSS (CWE-79) present in Dojo test files (_testCommon.js and runner.html). The root cause is insufficient input sanitization of URL parameters before they are inserted into the DOM. An attacker can craft a URL containing malicious JavaScript payload; when a victim visits this URL while using the affected test files, the unsanitized parameter is reflected into the page, causing the attacker's script to execute in the victim's browser context. The vulnerability affects Dojo versions 1.10.0 through 1.13.0 (fixed in 1.10.10, 1.11.6, 1.12.4, and 1.13.1). While the threat is primarily limited to developers accessing test files rather than end-users of applications built with Dojo, exploitation could allow credential theft or code injection during development.

Affected products

  • Dojo Project Dojo Toolkit 1.10.0 to 1.10.9, 1.11.0 to 1.11.5, 1.12.0 to 1.12.3, 1.13.0

Timeline

  • 2010-03: disclosed: Vulnerability publicly disclosed in Dojo security advisory
  • 2018-08-10: patched: Fix merged in commit 9117ffd5a3863e44c92fcd58564c0da22be858f4

References