Cross-Site Scripting in dojo
        
  Moderate severity
        
          GitHub Reviewed
      
        Published
          Sep 11, 2020 
          to the GitHub Advisory Database
          •
          Updated Jan 6, 2023 
      
  
Description
        Reviewed
      Aug 31, 2020 
    
  
        Published to the GitHub Advisory Database
      Sep 11, 2020 
    
  
        Last updated
      Jan 6, 2023 
    
  
Versions of
dojoprior to 1.2.0 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize HTML code in user-controlled input, allowing attackers to execute arbitrary JavaScript in the victim's browser.Recommendation
Upgrade to version 1.2.0 or later.
References