Description
In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid.
Remediation
References
https://dojotoolkit.org/blog/dojo-1-14-released
https://github.com/dojo/dojox/pull/283
https://lists.debian.org/debian-lts-announce/2018/09/msg00002.html
Related Vulnerabilities
CVE-2020-2219 Vulnerability in maven package org.jenkins-ci.plugins:link-column
CVE-2020-1947 Vulnerability in maven package org.apache.shardingsphere:shardingsphere
CVE-2023-29020 Vulnerability in npm package @fastify/passport
CVE-2023-24057 Vulnerability in maven package ca.uhn.hapi.fhir:org.hl7.fhir.r4b
CVE-2017-12624 Vulnerability in maven package org.apache.cxf:cxf-core