VDB
Sign up
MEDIUM6.1

GHSA-4m44-5j2g-xf64

Improper Neutralization of Input During Web Page Generation in CKEditor4

Quick fix

GHSA-4m44-5j2g-xf64 — ckeditor4: upgrade to the fixed version with the command below.

npm install ckeditor4@4.15.1

Details

A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/ckeditor4
Introduced in: 0Fixed in: 4.15.1
Fixnpm install ckeditor4@4.15.1

References