Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-48110

Опубликовано: 13 фев. 2023
Источник: nvd
CVSS3: 6.1
EPSS Низкий

Описание

CKSource CKEditor 5 35.4.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Full Featured CKEditor5 widget. NOTE: the vendor's position is that this is not a vulnerability. The CKEditor 5 documentation discusses that it is the responsibility of an integrator (who is adding CKEditor 5 functionality to a website) to choose the correct security settings for their use case. Also, safe default values are established (e.g., config.htmlEmbed.showPreviews is false).

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ckeditor:ckeditor:35.4.0:*:*:*:*:node.js:*:*

EPSS

Процентиль: 78%
0.01101
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 3 года назад

CKSource CKEditor 5 35.4.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Full Featured CKEditor5 widget. NOTE: the vendor's position is that this is not a vulnerability. The CKEditor 5 documentation discusses that it is the responsibility of an integrator (who is adding CKEditor 5 functionality to a website) to choose the correct security settings for their use case. Also, safe default values are established (e.g., config.htmlEmbed.showPreviews is false).

CVSS3: 6.1
github
почти 3 года назад

Cross-site scripting in CKEditor5

CVSS3: 6.1
fstec
почти 3 года назад

Уязвимость WYSIWYG-редактора CKEditor, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

EPSS

Процентиль: 78%
0.01101
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79