Reflected cross-site scripting (XSS) In ckeditor/ckeditor

Description

The Preview plugin in CKEditor allows Cross-site scripting (XSS) Cross-site scripting (XSS) vulnerability in the Preview plugin before 4.4.3 in CKEditor allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package
Affected version
Patched versions