{"id":"CVE-2018-1000665","aliases":["GHSA-vmq9-cm7m-4p8p"],"url":"https://o3.security/vulnerability/CVE-2018-1000665","summary":"Improper Neutralization of Input During Web Page Generation in Dojo Dojo Objective Harness","details":"Dojo Dojo Objective Harness (DOH) version prior to version 1.14 contains a Cross Site Scripting (XSS) vulnerability in unit.html and testsDOH/_base/loader/i18n-exhaustive/i18n-test/unit.html and testsDOH/_base/i18nExhaustive.js in the DOH that can result in Victim attacked through their browser - deliver malware, steal HTTP cookies, bypass CORS trust. This attack appear to be exploitable via Victims are typically lured to a web site under the attacker's control; the XSS vulnerability on the target domain is silently exploited without the victim's knowledge. This vulnerability appears to have been fixed in 1.14.","published":"2018-09-06T17:29:01.597Z","modified":"2026-07-08T14:58:55.404631Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.dojotoolkit:dojo","fixedVersion":"1.14"}],"fix":{"url":"https://github.com/dojo/dojo/pull/307","label":"dojo/dojo#307"},"references":[{"type":"ADVISORY","url":"https://github.com/dojo/dojo/pull/307"},{"type":"FIX","url":"https://dojotoolkit.org/blog/dojo-1-14-released"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000665"},{"type":"PACKAGE","url":"https://github.com/dojo/dojo"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T14:58:55.404631Z"}}