Description
The vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4.
Recommendation
Update the ckeditor4 package to the latest compatible version. Followings are version details:
- Affected version(s): < 4.18.0
- Patched version(s): 4.18.0
References
- GHSA-4fc4-4p5g-6w89
- ckeditor.com
- www.drupal.org
- www.oracle.com
- lists.fedoraproject.org
- CVE-2022-24728
- CWE-79
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- Toast UI Grid vulnerable to Cross-site Scripting - CVE-2022-23458
- materialize-css vulnerable to cross-site Scripting (XSS) due to improper escape of user input - CVE-2022-25349
- Cross-site Scripting in jquery.json-viewer - CVE-2022-30241
- CKEditor cross-site scripting vulnerability in AJAX sample - CVE-2023-4771
You might also like:
- Tags:
- npm
- ckeditor4
Anything's wrong? Let us know Last updated on January 27, 2023


