Description
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14.0 allows remote attackers to inject arbitrary web script through a crafted “protected” comment (with the cke_protected syntax).
Recommendation
Update the ckeditor4 package to the latest compatible version. Followings are version details:
- Affected version(s): < 4.14.0
- Patched version(s): 4.14.0
References
- GHSA-vcjf-mgcg-jxjq
- lists.fedoraproject.org
- www.oracle.com
- CVE-2020-9281
- CWE-79
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- CKEditor5 cross-site scripting vulnerability caused by the editor instance destroying process - @ckeditor/ckeditor5-html-support - CVE-2022-31175
- CKEditor cross-site scripting vulnerability in AJAX sample - CVE-2023-4771
- Advanced Content Filter (ACF) vulnerability allowing to execute JavaScript code using malformed HTML - CVE-2021-41164
- HTML comments vulnerability allowing to execute JavaScript code - CVE-2021-41165
You might also like:
- Tags:
- npm
- ckeditor4
Anything's wrong? Let us know Last updated on March 31, 2023


