Description
dijit.Editor in Dojo Toolkit 1.13 allows XSS via the onload attribute of an SVG element.
Remediation
References
https://github.com/imsebao/404team/blob/master/dijit_editor_xss.md
Related Vulnerabilities
CVE-2021-23358 Vulnerability in maven package org.webjars.bower:underscore
CVE-2022-31139 Vulnerability in maven package io.github.karlatemp:unsafe-accessor
CVE-2020-15096 Vulnerability in npm package electron
CVE-2017-11555 Vulnerability in maven package org.webjars.npm:node-sass
CVE-2021-41532 Vulnerability in maven package org.apache.ozone:ozone-recon