CVE-2018-15494: Critical severity Dojotoolkit Dojo vulnerability
In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid.
Other sources
In Dojo Toolkit before 1.14.0, there is unescaped string injection in dojox/Grid/DataGrid.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-15494?
CVE-2018-15494 is a vulnerability in Dojo Toolkit before version 1.14 that allows for unescaped string injection in the dojox/Grid/DataGrid component.
How does CVE-2018-15494 impact Dojo Toolkit?
CVE-2018-15494 is a critical vulnerability that allows remote attackers to inject malicious scripts into web pages using the DataGrid component.
Which software versions are affected by CVE-2018-15494?
Dojo Toolkit versions before 1.14, Debian Linux version 8.0, and IBM Security Verify Access Docker version up to 10.0.0 are affected.
How can I fix CVE-2018-15494?
To fix CVE-2018-15494, update Dojo Toolkit to version 1.14.0 or newer.
Where can I find more information about CVE-2018-15494?
You can find more information about CVE-2018-15494 on the NIST National Vulnerability Database (NVD) at https://nvd.nist.gov/vuln/detail/CVE-2018-15494 and on the official Dojo Toolkit blog at https://dojotoolkit.org/blog/dojo-1-14-released.