Improper Neutralization of Input During Web Page Generation in CKEditor4
- Severity:
- Medium
Description
A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.
Recommendation
Update the ckeditor4 package to the latest compatible version. Followings are version details:
- Affected version(s): <= 4.15.0
- Patched version(s): 4.15.1
References
- GHSA-4m44-5j2g-xf64
- ckeditor.com
- www.oracle.com
- CVE-2020-27193
- CWE-79
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- Materialize-css vulnerable to Improper Neutralization of Input During Web Page Generation - materialize-css - CVE-2019-11004
- Materialize-css vulnerable to Improper Neutralization of Input During Web Page Generation - CVE-2019-11004
- Improper Neutralization of Input During Web Page Generation in Select2 - CVE-2016-10744
- Improper Neutralization of Input During Web Page Generation in swagger-ui - CVE-2016-1000229
You might also like:
- Tags:
- npm
- ckeditor4
Anything's wrong? Let us know Last updated on January 27, 2023


