Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-9861

Опубликовано: 19 апр. 2018
Источник: ubuntu
Приоритет: medium
CVSS2: 4.3
CVSS3: 6.1

Описание

Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor (in versions 4.5.10 through 4.9.1; fixed in 4.9.2), as used in Drupal 8 before 8.4.7 and 8.5.x before 8.5.2 and other products, allows remote attackers to inject arbitrary web script through a crafted IMG element.

РелизСтатусПримечание
artful

ignored

end of life
bionic

released

4.5.7+dfsg-2ubuntu0.18.04.1
cosmic

ignored

end of life
devel

not-affected

4.16.2+dfsg-1
disco

ignored

end of life
eoan

ignored

end of life
esm-apps/bionic

released

4.5.7+dfsg-2ubuntu0.18.04.1
esm-apps/focal

not-affected

4.12.1+dfsg-1
esm-apps/jammy

not-affected

4.16.2+dfsg-1
esm-apps/xenial

released

4.5.7+dfsg-2ubuntu0.16.04.1~esm1

Показывать по

4.3 Medium

CVSS2

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
около 7 лет назад

Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor (in versions 4.5.10 through 4.9.1; fixed in 4.9.2), as used in Drupal 8 before 8.4.7 and 8.5.x before 8.5.2 and other products, allows remote attackers to inject arbitrary web script through a crafted IMG element.

CVSS3: 6.1
github
около 3 лет назад

Enhanced Image plugin for CKEditor is vulnerable to Cross-site scripting (XSS)

4.3 Medium

CVSS2

6.1 Medium

CVSS3