Description
dijit.Editor in Dojo Toolkit 1.13 allows XSS via the onload attribute of an SVG element.
Remediation
References
https://github.com/imsebao/404team/blob/master/dijit_editor_xss.md
Related Vulnerabilities
CVE-2020-7748 Vulnerability in npm package @tsed/core
CVE-2023-28155 Vulnerability in maven package org.webjars:request
CVE-2021-25646 Vulnerability in maven package org.apache.druid:druid-core
CVE-2020-7713 Vulnerability in npm package arr-flatten-unflatten
CVE-2022-25758 Vulnerability in maven package org.webjars.npm:scss-tokenizer