CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:N/C:N/I:P/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
Percentile
36.2%
Dojo Dojo Objective Harness (DOH) version prior to version 1.14 contains a
Cross Site Scripting (XSS) vulnerability in unit.html and
testsDOH/_base/loader/i18n-exhaustive/i18n-test/unit.html and
testsDOH/_base/i18nExhaustive.js in the DOH that can result in Victim
attacked through their browser - deliver malware, steal HTTP cookies,
bypass CORS trust. This attack appear to be exploitable via Victims are
typically lured to a web site under the attacker’s control; the XSS
vulnerability on the target domain is silently exploited without the
victim’s knowledge. This vulnerability appears to have been fixed in 1.14.
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:N/C:N/I:P/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
Percentile
36.2%