668
VMScore

CVE-2018-15494

Published: 18/08/2018 Updated: 24/08/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

In Dojo Toolkit prior to 1.14, there is unescaped string injection in dojox/Grid/DataGrid.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dojotoolkit dojo

debian debian linux 8.0

Vendor Advisories

Debian Bug report logs - #906540 dojo: CVE-2018-15494 Package: src:dojo; Maintainer for src:dojo is Debian Javascript Maintainers <pkg-javascript-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 18 Aug 2018 08:48:02 UTC Severity: important Tags: fixed-upstream, security ...

Exploits

Dojo Toolkit version 113 suffers from a cross site scripting vulnerability ...