MEDIUM6.1
GHSA-4m44-5j2g-xf64
Improper Neutralization of Input During Web Page Generation in CKEditor4
Quick fix
GHSA-4m44-5j2g-xf64 — ckeditor4: upgrade to the fixed version with the command below.
npm install ckeditor4@4.15.1Details
A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-27193[ADVISORY]
- https://ckeditor.com/blog/CKEditor-4.15.1-with-a-security-patch-released[WEB]
- https://ckeditor.com/cke4/release/CKEditor-4.15.1[WEB]
- https://ckeditor.com/ckeditor-4/download[WEB]
- https://github.com/ckeditor/ckeditor4[PACKAGE]
- https://www.oracle.com//security-alerts/cpujul2021.html[WEB]
- https://www.oracle.com/security-alerts/cpuApr2021.html[WEB]
- https://www.oracle.com/security-alerts/cpuoct2021.html[WEB]