CVE-2019-10785Cross-site Scripting in Dojox

CWE-79Cross-site Scripting11 documents8 sources
Severity
6.1MEDIUMNVD
EPSS
0.2%
top 52.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 13
Latest updateJun 16

Description

dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9. This is due to dojox.xmpp.util.xmlEncode only encoding the first occurrence of each character, not all of them.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages4 packages

NVDlinuxfoundation/dojox1.11.01.11.9+5
npmlinuxfoundation/dojox1.12.01.12.7+5
CVEListV5linuxfoundation/dojoxall versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9.
Debianlinuxfoundation/dojo< 1.15.2+dfsg1-1+3

Also affects: Debian Linux 8.0

🔴Vulnerability Details

5
OSV
dojo vulnerabilities2025-06-16
GHSA
XSS in dojox due to insufficient escape in dojox.xmpp.util.xmlEncode2020-02-13
CVEList
CVE-2019-10785: dojox is vulnerable to Cross-site Scripting in all versions before version 12020-02-13
OSV
CVE-2019-10785: dojox is vulnerable to Cross-site Scripting in all versions before version 12020-02-13
OSV
XSS in dojox due to insufficient escape in dojox.xmpp.util.xmlEncode2020-02-13

📋Vendor Advisories

3
Ubuntu
Dojo vulnerabilities2025-06-16
Red Hat
dojo: cross-site scripting via dojox.xmpp.util.xmlEncode2020-02-28
Debian
CVE-2019-10785: dojo - dojox is vulnerable to Cross-site Scripting in all versions before version 1.16....2019

💬Community

2
Bugzilla
CVE-2019-10785 dojo: cross-site scripting via dojox.xmpp.util.xmlEncode2020-05-04
Bugzilla
CVE-2019-10785 dojo: cross-site scripting via dojox.xmpp.util.xmlEncode [epel-all]2020-05-04
CVE-2019-10785 — Cross-site Scripting in Dojox | cvebase