VDB
Sign up
—

DRUPAL-CONTRIB-2024-009

Details

The CKEditor 4 LTS - WYSIWYG HTML editor module uses the CKEditor library for WYSIWYG editing. CKEditor has released a [security update](https://ckeditor.com/cke4/release/CKEditor-4.24.0-LTS) that on certain configurations may impact the Drupal module that bundles and integrates this code.

The vulnerability is mitigated by the fact it requires:

1. [full-page editing](https://ckeditor.com/docs/ckeditor4/latest/features/fullpage.html) mode is enabled 2. or CDATA elements in Advanced Content Filtering configuration (defaults to script and style elements) are enabled. 3. An attacker must have a permission with access to the CKEditor instance.

For more information, see CKEditor's security advisory: [CVE-2024-24815](https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-fq6h-4g8v-qqvm): Cross-site scripting (XSS) vulnerability caused by incorrect CDATA detection

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist:https://packages.drupal.org/8/drupal/ckeditor_lts
Introduced in: 1.0.0Fixed in: 1.0.1

Upgrade drupal/ckeditor_lts to 1.0.1 or newer (ecosystem packagist:https://packages.drupal.org/8).

References