Description
The vulnerability has been discovered in Code Snippet GeSHi plugin. All integrators that use GeSHi syntax highlighter on the backend side can be affected.
Recommendation
Update the ckeditor4 package to the latest compatible version. Followings are version details:
- Affected version(s): < 4.25.0
- Patched version(s): 4.25.0
References
Could your website be exposed too?
SmartScanner can check your website for Code Snippet GeSHi plugin in CKEditor 4 has reflected cross-site scripting (XSS) vulnerability and gives you actionable findings to investigate.
Start a free scanRelated Issues
- VvvebJs Reflected Cross-Site Scripting (XSS) vulnerability - CVE-2024-29271
- CKEditor4 low-risk cross-site scripting (XSS) vulnerability linked to potential domain takeover - CVE-2024-43411
- TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements - CVE-2024-29881
- vue-i18n has cross-site scripting vulnerability with prototype pollution - @intlify/vue-i18n-core - CVE-2024-52809


