VDB
Sign up
MEDIUM6.1

GHSA-wh5w-82f3-wrxh

CKEditor cross-site scripting vulnerability in AJAX sample

Quick fix

GHSA-wh5w-82f3-wrxh — ckeditor4: upgrade to the fixed version with the command below.

npm install ckeditor4@4.24.0-lts

Details

### Affected packages The vulnerability has been discovered in the AJAX sample available at the `samples/old/ajax.html` file location. All integrators that use that sample in the production code can be affected.

### Impact

A potential vulnerability has been discovered in one of CKEditor's 4 samples that are shipped with production code. The vulnerability allowed to execute JavaScript code by abusing the AJAX sample. It affects all users using the CKEditor 4 at version < 4.24.0-lts where `samples/old/ajax.html` is used in a production environment.

### Patches The problem has been recognized and patched. The fix will be available in version 4.24.0-lts.

### For more information Email us at [security@cksource.com](mailto:security@cksource.com) if you have any questions or comments about this advisory.

### Acknowledgements The CKEditor 4 team would like to thank Rafael Pedrero and INCIBE ([original report](https://www.incibe.es/en/incibe-cert/notices/aviso/cross-site-scripting-vulnerability-cksource-ckeditor)) for recognizing and reporting this vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/ckeditor4
Introduced in: 0Fixed in: 4.24.0-lts
Fixnpm install ckeditor4@4.24.0-lts

References