VDB
Sign up
MEDIUM6.1

GHSA-g68x-vvqq-pvw3

Ckeditor XSS Vulnerability

Quick fix

GHSA-g68x-vvqq-pvw3 — ckeditor: upgrade to the fixed version with the command below.

npm install ckeditor@4.11.0

Details

CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste. It was possible to execute XSS inside the CKEditor source area after persuading the victim to: (i) switch CKEditor to source mode, then (ii) paste a specially crafted HTML code, prepared by the attacker, into the opened CKEditor source area, and (iii) switch back to WYSIWYG mode. Although this is an unlikely scenario, it is recommended to upgrade to the latest editor version.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/ckeditor
Introduced in: 0Fixed in: 4.11.0
Fixnpm install ckeditor@4.11.0
Packagist/typo3/cms-core
Introduced in: 8.0.0Fixed in: 8.7.21
Fixcomposer require typo3/cms-core:^8.7.21
Packagist/typo3/cms-core
Introduced in: 9.0.0Fixed in: 9.5.2
Fixcomposer require typo3/cms-core:^9.5.2
Packagist/typo3/cms
Introduced in: 8.0.0Fixed in: 8.7.21
Fixcomposer require typo3/cms:^8.7.21
Packagist/typo3/cms
Introduced in: 9.0.0Fixed in: 9.5.2
Fixcomposer require typo3/cms:^9.5.2

References