Executive brief
Dojo's dijit library includes an editor component with a LinkDialog plugin used for inserting hyperlinks into rich text. A cross-site scripting (XSS) vulnerability in this plugin allows an attacker with user interaction to inject malicious scripts, potentially compromising the security and integrity of edited content for users of applications embedding this editor.
Technical details
This is a cross-site scripting (CWE-79) vulnerability in the LinkDialog plugin of the Dojo dijit editor component. The vulnerability affects multiple release branches of dijit (versions before 1.11.11, 1.12.0 through 1.12.8, 1.13.0 through 1.13.7, 1.14.0 through 1.14.6, 1.15.0 through 1.15.3, and 1.16.0 through 1.16.2). The attack vector is network-based and requires user interaction (UI:R), along with low privilege level (PR:L), allowing an attacker to inject unsanitized content through the link dialog. Patches are available in versions 1.11.11, 1.12.9, 1.13.8, 1.14.7, 1.15.4, and 1.16.3 or later.
Affected products
- The Dojo Foundation dijit before 1.11.11, 1.12.0-1.12.8, 1.13.0-1.13.7, 1.14.0-1.14.6, 1.15.0-1.15.3, 1.16.0-1.16.2
Timeline
- 2020-06-15: disclosed
- 2020-06-15: patched: Patches released in versions 1.11.11, 1.12.9, 1.13.8, 1.14.7, 1.15.4, 1.16.3