Логотип exploitDog
bind:CVE-2024-24815
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-24815

Количество 5

Количество 5

ubuntu логотип

CVE-2024-24815

около 2 лет назад

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been discovered in the core HTML parsing module in versions of CKEditor4 prior to 4.24.0-lts. It may affect all editor instances that enabled full-page editing mode or enabled CDATA elements in Advanced Content Filtering configuration (defaults to `script` and `style` elements). The vulnerability allows attackers to inject malformed HTML content bypassing Advanced Content Filtering mechanism, which could result in executing JavaScript code. An attacker could abuse faulty CDATA content detection and use it to prepare an intentional attack on the editor. A fix is available in version 4.24.0-lts.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2024-24815

около 2 лет назад

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been discovered in the core HTML parsing module in versions of CKEditor4 prior to 4.24.0-lts. It may affect all editor instances that enabled full-page editing mode or enabled CDATA elements in Advanced Content Filtering configuration (defaults to `script` and `style` elements). The vulnerability allows attackers to inject malformed HTML content bypassing Advanced Content Filtering mechanism, which could result in executing JavaScript code. An attacker could abuse faulty CDATA content detection and use it to prepare an intentional attack on the editor. A fix is available in version 4.24.0-lts.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2024-24815

около 2 лет назад

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. ...

CVSS3: 6.1
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2025:0008-1

около 1 года назад

Security update for python-django-ckeditor

EPSS: Низкий
github логотип

GHSA-fq6h-4g8v-qqvm

около 2 лет назад

CKEditor4 Cross-site Scripting vulnerability caused by incorrect CDATA detection

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-24815

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been discovered in the core HTML parsing module in versions of CKEditor4 prior to 4.24.0-lts. It may affect all editor instances that enabled full-page editing mode or enabled CDATA elements in Advanced Content Filtering configuration (defaults to `script` and `style` elements). The vulnerability allows attackers to inject malformed HTML content bypassing Advanced Content Filtering mechanism, which could result in executing JavaScript code. An attacker could abuse faulty CDATA content detection and use it to prepare an intentional attack on the editor. A fix is available in version 4.24.0-lts.

CVSS3: 6.1
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-24815

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been discovered in the core HTML parsing module in versions of CKEditor4 prior to 4.24.0-lts. It may affect all editor instances that enabled full-page editing mode or enabled CDATA elements in Advanced Content Filtering configuration (defaults to `script` and `style` elements). The vulnerability allows attackers to inject malformed HTML content bypassing Advanced Content Filtering mechanism, which could result in executing JavaScript code. An attacker could abuse faulty CDATA content detection and use it to prepare an intentional attack on the editor. A fix is available in version 4.24.0-lts.

CVSS3: 6.1
0%
Низкий
около 2 лет назад
debian логотип
CVE-2024-24815

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. ...

CVSS3: 6.1
0%
Низкий
около 2 лет назад
suse-cvrf логотип
openSUSE-SU-2025:0008-1

Security update for python-django-ckeditor

0%
Низкий
около 1 года назад
github логотип
GHSA-fq6h-4g8v-qqvm

CKEditor4 Cross-site Scripting vulnerability caused by incorrect CDATA detection

CVSS3: 6.1
0%
Низкий
около 2 лет назад

Уязвимостей на страницу