Executive brief
dijit Editor is a rich text editor component in the Dojo Toolkit framework used to build web applications. An attacker can inject malicious JavaScript by crafting SVG elements with event handlers (such as onload attributes) in edited content, allowing them to execute code in the browser of any user viewing the content. This could lead to session hijacking, credential theft, or defacement.
Technical details
The vulnerability is a cross-site scripting (XSS) flaw in dijit.Editor (CWE-79) that fails to properly sanitize event handler attributes on SVG elements during content editing. The root cause is insufficient filtering of dangerous attributes on inline SVG tags. An attacker with the ability to inject or edit content through the Editor (no authentication required if the editor is exposed) can craft an SVG element with an onload attribute containing JavaScript code. When the edited content is rendered or displayed to other users, the JavaScript executes in their browsers with the privileges of the affected application. The fix, released in dijit version 1.13.1, removes event handler attributes from tags in the editor's contents.
Affected products
- Dojo dijit through 1.13.0
Timeline
- 2018-02-02: disclosed
- 2018: patched: Fixed in dijit 1.13.1