VDB
Sign up
MEDIUM6.1

GHSA-vcjf-mgcg-jxjq

CKEditor 4.0 vulnerability in the HTML Data Processor

Quick fix

GHSA-vcjf-mgcg-jxjq — ckeditor4: upgrade to the fixed version with the command below.

npm install ckeditor4@4.14.0

Details

A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14.0 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/ckeditor4
Introduced in: 0Fixed in: 4.14.0
Fixnpm install ckeditor4@4.14.0

References