Show filters
20 Total Results
Displaying 1-10 of 20
Sort by:
Attacker Value
Unknown

CVE-2025-24886

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
pwn.college is an education platform to learn about, and practice, core cybersecurity concepts in a hands-on fashion. Incorrect symlink checks on user specified dojos allows for users (admin not required) to perform an LFI from the CTFd container. When a user clones or updates repositories, a check is performed to see if the repository had contained any symlinks. A malicious user could craft a repository with symlinks pointed to sensitive files and then retrieve them using the CTFd website.
0
Attacker Value
Unknown

CVE-2025-24885

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
pwn.college is an education platform to learn about, and practice, core cybersecurity concepts in a hands-on fashion. Missing access control on rendering custom (unprivileged) dojo pages causes ability for users to create stored XSS.
0
Attacker Value
Unknown

CVE-2023-48171

Disclosure Date: August 12, 2024 (last updated September 19, 2024)
An issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via the user permissions component.
Attacker Value
Unknown

CVE-2021-23450

Disclosure Date: December 17, 2021 (last updated October 07, 2023)
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
Attacker Value
Unknown

CVE-2020-5259

Disclosure Date: March 10, 2020 (last updated February 21, 2025)
In affected versions of dojox (NPM package), the jqMix method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript application object prototype of the base object by injecting other values. This has been patched in versions 1.11.10, 1.12.8, 1.13.7, 1.14.6, 1.15.3 and 1.16.2
Attacker Value
Unknown

CVE-2020-5258

Disclosure Date: March 10, 2020 (last updated February 21, 2025)
In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript application object prototype of the base object by injecting other values. This has been patched in versions 1.12.8, 1.13.7, 1.14.6, 1.15.3 and 1.16.2
0
Attacker Value
Unknown

CVE-2019-10785

Disclosure Date: February 13, 2020 (last updated February 21, 2025)
dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9. This is due to dojox.xmpp.util.xmlEncode only encoding the first occurrence of each character, not all of them.
Attacker Value
Unknown

CVE-2018-1000665

Disclosure Date: September 06, 2018 (last updated November 27, 2024)
Dojo Dojo Objective Harness (DOH) version prior to version 1.14 contains a Cross Site Scripting (XSS) vulnerability in unit.html and testsDOH/_base/loader/i18n-exhaustive/i18n-test/unit.html and testsDOH/_base/i18nExhaustive.js in the DOH that can result in Victim attacked through their browser - deliver malware, steal HTTP cookies, bypass CORS trust. This attack appear to be exploitable via Victims are typically lured to a web site under the attacker's control; the XSS vulnerability on the target domain is silently exploited without the victim's knowledge. This vulnerability appears to have been fixed in 1.14.
0
Attacker Value
Unknown

CVE-2018-15494

Disclosure Date: August 18, 2018 (last updated November 27, 2024)
In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid.
0
Attacker Value
Unknown

CVE-2018-6561

Disclosure Date: February 02, 2018 (last updated November 26, 2024)
dijit.Editor in Dojo Toolkit 1.13 allows XSS via the onload attribute of an SVG element.
0