Description
The vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4.
Recommendation
Update the ckeditor4 package to the latest compatible version. Followings are version details:
- Affected version(s): < 4.17.0
- Patched version(s): 4.17.0
References
- GHSA-7h26-63m7-qhf2
- www.drupal.org
- www.oracle.com
- CVE-2021-41165
- CWE-79
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- Advanced Content Filter (ACF) vulnerability allowing to execute JavaScript code using malformed HTML - CVE-2021-41164
- Fake objects feature vulnerability allowing to execute JavaScript code using malformed HTML. - CVE-2021-37695
- Widget feature vulnerability allowing to execute JavaScript code using undo functionality - CVE-2021-32808
- Clipboard feature vulnerability allowing to inject arbitrary HTML into the editor using paste functionality - CVE-2021-32809
You might also like:
- Tags:
- npm
- ckeditor4
Anything's wrong? Let us know Last updated on December 28, 2023


