Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2019-10785
Description:dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9. This is due to dojox.xmpp.util.xmlEncode only encoding the first occurrence of each character, not all of them.
Test IDs: 1.3.6.1.4.1.25623.1.1.10.2020.0126   1.3.6.1.4.1.25623.1.0.892127  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2019-10785
https://github.com/dojo/dojox/security/advisories/GHSA-pg97-ww7h-5mjr
https://snyk.io/vuln/SNYK-JS-DOJOX-548257,
https://lists.debian.org/debian-lts-announce/2020/02/msg00033.html




© 1998-2025 E-Soft Inc. All rights reserved.