{"id":"CVE-2008-6681","aliases":[],"url":"https://o3.security/vulnerability/CVE-2008-6681","summary":"Cross-Site Scripting in dojo","details":"Affected versions of `dojo` are susceptible to a cross-site scripting vulnerability in the `dijit.Editor` and `textarea` components, which execute their contents as Javascript, even when sanitized.\n\n\n## Recommendation\n\nUpdate to version 1.1.0 or later.","published":"2020-09-01T15:25:29Z","modified":"2023-11-08T03:56:52.043077Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"npm","name":"dojo","fixedVersion":"1.1.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2008-6681"},{"type":"WEB","url":"https://bugs.dojotoolkit.org/ticket/2140"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/49883"},{"type":"WEB","url":"https://www.npmjs.com/advisories/107"},{"type":"WEB","url":"http://trac.dojotoolkit.org/changeset/15346"},{"type":"WEB","url":"http://trac.dojotoolkit.org/ticket/2140"},{"type":"WEB","url":"http://www.dojotoolkit.org/book/dojo-1-1-release-notes"},{"type":"WEB","url":"http://www.securityfocus.com/bid/34661"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T03:56:52.043077Z"}}