Описание
Improper Neutralization of Input During Web Page Generation in CKEditor4
A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2020-27193
- https://ckeditor.com/blog/CKEditor-4.15.1-with-a-security-patch-released
- https://ckeditor.com/cke4/release/CKEditor-4.15.1
- https://ckeditor.com/ckeditor-4/download
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
Пакеты
Наименование
ckeditor4
npm
Затронутые версииВерсия исправления
<= 4.15.0
4.15.1
Связанные уязвимости
CVSS3: 6.1
nvd
около 5 лет назад
A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.
CVSS3: 6.1
fstec
около 5 лет назад
Уязвимость плагина Color Dialog WYSIWYG-редактора CKEditor, позволяющая нарушителю проводить межсайтовые сценарные атаки