CVE-2020-4051 Information
Description
In Dijit before versions 1.11.11 and greater than or equal to 1.12.0 and less than 1.12.9 and greater than or equal to 1.13.0 and less than 1.13.8 and greater than or equal to 1.14.0 and less than 1.14.7 and greater than or equal to 1.15.0 and less than 1.15.4 and greater than or equal to 1.16.0 and less than 1.16.3 there is a cross-site scripting vulnerability in the Editor’s LinkDialog plugin. This has been fixed in 1.11.11 1.12.9 1.13.8 1.14.7 1.15.4 1.16.3.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Reference
https://github.com/dojo/dijit/commit/462bdcd60d0333315fe69ab4709c894d78f61301 https://github.com/dojo/dijit/security/advisories/GHSA-cxjc-r2fp-7mq6 https://security.netapp.com/advisory/ntap-20201023-0003/ https://www.oracle.com/security-alerts/cpuoct2020.html
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
4.6
Share on: