Логотип exploitDog
bind:CVE-2022-48110
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-48110

Количество 4

Количество 4

ubuntu логотип

CVE-2022-48110

почти 3 года назад

CKSource CKEditor 5 35.4.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Full Featured CKEditor5 widget. NOTE: the vendor's position is that this is not a vulnerability. The CKEditor 5 documentation discusses that it is the responsibility of an integrator (who is adding CKEditor 5 functionality to a website) to choose the correct security settings for their use case. Also, safe default values are established (e.g., config.htmlEmbed.showPreviews is false).

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2022-48110

почти 3 года назад

CKSource CKEditor 5 35.4.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Full Featured CKEditor5 widget. NOTE: the vendor's position is that this is not a vulnerability. The CKEditor 5 documentation discusses that it is the responsibility of an integrator (who is adding CKEditor 5 functionality to a website) to choose the correct security settings for their use case. Also, safe default values are established (e.g., config.htmlEmbed.showPreviews is false).

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-6p89-3p7c-qrhv

почти 3 года назад

Cross-site scripting in CKEditor5

CVSS3: 6.1
EPSS: Низкий
fstec логотип

BDU:2023-05266

почти 3 года назад

Уязвимость WYSIWYG-редактора CKEditor, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-48110

CKSource CKEditor 5 35.4.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Full Featured CKEditor5 widget. NOTE: the vendor's position is that this is not a vulnerability. The CKEditor 5 documentation discusses that it is the responsibility of an integrator (who is adding CKEditor 5 functionality to a website) to choose the correct security settings for their use case. Also, safe default values are established (e.g., config.htmlEmbed.showPreviews is false).

CVSS3: 6.1
1%
Низкий
почти 3 года назад
nvd логотип
CVE-2022-48110

CKSource CKEditor 5 35.4.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Full Featured CKEditor5 widget. NOTE: the vendor's position is that this is not a vulnerability. The CKEditor 5 documentation discusses that it is the responsibility of an integrator (who is adding CKEditor 5 functionality to a website) to choose the correct security settings for their use case. Also, safe default values are established (e.g., config.htmlEmbed.showPreviews is false).

CVSS3: 6.1
1%
Низкий
почти 3 года назад
github логотип
GHSA-6p89-3p7c-qrhv

Cross-site scripting in CKEditor5

CVSS3: 6.1
1%
Низкий
почти 3 года назад
fstec логотип
BDU:2023-05266

Уязвимость WYSIWYG-редактора CKEditor, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

CVSS3: 6.1
1%
Низкий
почти 3 года назад

Уязвимостей на страницу