VDB
Sign up
MEDIUM6.1

GHSA-q9w4-w667-qqj4

ckeditor-wordcount-plugin vulnerable to Cross-site Scripting in Source Mode of Editor

Quick fix

GHSA-q9w4-w667-qqj4 — ckeditor-wordcount-plugin: upgrade to the fixed version with the command below.

npm install ckeditor-wordcount-plugin@1.17.12

Details

### Problem

It has been discovered that the `ckeditor-wordcount-plugin` plugin for CKEditor4 is susceptible to cross-site scripting when switching to the source code mode.

### Solution

Update to version 1.17.12 of the `ckeditor-wordcount-plugin` plugin.

### Credits

* @sypets for reporting this finding to the TYPO3 Security Team * @ohader for fixing the issue on behalf of the TYPO3 Security Team

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/ckeditor-wordcount-plugin
Introduced in: 0Fixed in: 1.17.12
Fixnpm install ckeditor-wordcount-plugin@1.17.12

References