Ckeditor XSS Vulnerability
Moderate severity
GitHub Reviewed
Published
Nov 21, 2018
to the GitHub Advisory Database
•
Updated Feb 5, 2024
Description
Published to the GitHub Advisory Database
Nov 21, 2018
Reviewed
Jun 16, 2020
Last updated
Feb 5, 2024
CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste. It was possible to execute XSS inside the CKEditor source area after persuading the victim to: (i) switch CKEditor to source mode, then (ii) paste a specially crafted HTML code, prepared by the attacker, into the opened CKEditor source area, and (iii) switch back to WYSIWYG mode. Although this is an unlikely scenario, it is recommended to upgrade to the latest editor version.
References