Reflected cross-site scripting (XSS) In ckeditor4
Description
CKEditor 4.0 vulnerability in the HTML Data Processor A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14.0 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
npm | 4.14.0 | ||
packagist | 8.7.12, 8.8.4 | ||
packagist | 8.7.12, 8.8.4 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4. 5. 6. 7. 8.