Description
CKSource CKEditor5 35.4.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Full Featured CKEditor5 widget.
NOTE: the vendor’s position is that this is not a vulnerability.
Recommendation
Update the ckeditor5 package to the latest compatible version. Followings are version details:
- Affected version(s): < 36.0.0
- Patched version(s): 36.0.0
References
- GHSA-6p89-3p7c-qrhv
- ckeditor.com
- packetstormsecurity.com
- CVE-2022-48110
- CWE-79
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- CKEditor5 cross-site scripting vulnerability caused by the editor instance destroying process - @ckeditor/ckeditor5-html-support - CVE-2022-31175
- CKEditor5 cross-site scripting vulnerability caused by the editor instance destroying process - @ckeditor/ckeditor5-markdown-gfm - CVE-2022-31175
- CKEditor5 cross-site scripting vulnerability caused by the editor instance destroying process - CVE-2022-31175
- Cross-site Scripting in bootstrap-table - CVE-2022-1726
You might also like:
- Tags:
- npm
- ckeditor5
Anything's wrong? Let us know Last updated on February 23, 2023


