In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid.
CPE | Name | Operator | Version |
---|---|---|---|
dojo | eq | 1.12.0 | |
dojo | eq | 1.12.0-rc1 | |
dojo | eq | 1.11.0-rc1 | |
dojo | eq | 1.10.0-beta1 | |
dojo | eq | 1.11.0-rc4 | |
dojo | eq | 1.11.0-rc3 | |
dojo | eq | 1.12.0-rc2 | |
dojo | eq | 1.11.0-rc5 | |
dojo | eq | 1.11.0-rc2 | |
dojo | eq | 1.12.0-rc3 |