4.3
CVSSv2

CVE-2018-6561

Published: 02/02/2018 Updated: 15/02/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

dijit.Editor in Dojo Toolkit 1.13 allows XSS via the onload attribute of an SVG element.

Vulnerable Product Search on Vulmon Subscribe to Product

dojotoolkit dojo 1.13.0

Vendor Advisories

Debian Bug report logs - #898944 CVE-2018-6561 Package: src:dojo; Maintainer for src:dojo is Debian Javascript Maintainers <pkg-javascript-devel@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Thu, 17 May 2018 16:57:01 UTC Severity: grave Tags: security Fixed in version dojo/1130+d ...
dijitEditor in Dojo Toolkit 113 allows XSS via the onload attribute of an SVG element ...