4.3
CVSSv2

CVE-2018-1000665

Published: 06/09/2018 Updated: 07/11/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Dojo Dojo Objective Harness (DOH) version prior to version 1.14 contains a Cross Site Scripting (XSS) vulnerability in unit.html and testsDOH/_base/loader/i18n-exhaustive/i18n-test/unit.html and testsDOH/_base/i18nExhaustive.js in the DOH that can result in Victim attacked through their browser - deliver malware, steal HTTP cookies, bypass CORS trust. This attack appear to be exploitable via Victims are typically lured to a web site under the attacker's control; the XSS vulnerability on the target domain is silently exploited without the victim's knowledge. This vulnerability appears to have been fixed in 1.14.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dojotoolkit dojo

Vendor Advisories

Dojo Dojo Objective Harness (DOH) version prior to version 114 contains a Cross Site Scripting (XSS) vulnerability in unithtml and testsDOH/_base/loader/i18n-exhaustive/i18n-test/unithtml and testsDOH/_base/i18nExhaustivejs in the DOH that can result in Victim attacked through their browser - deliver malware, steal HTTP cookies, bypass CORS tru ...