← Back

CVE-2021-41164

nvd nist
Published: Nov 17, 2021Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0. The problem has been recognized and patched. The fix will be available in version 4.17.0.

Affected (23)

Show all products
1 product
Ckeditor
1 product
Drupal
7 products
Banking Apis
Banking Digital Experience
Agile Plm
Application Express
Commerce Guided Search
Peoplesoft Enterprise Peopletools
Webcenter Portal
1 product
Fedora
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 4.0 to 4.17.0
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Drupal
From 8.9.0 to 8.9.20
From 9.1.0 to 9.1.14
From 9.2.0 to 9.2.9
Configuration C
10 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
From 18.1 to 18.3
Version 19.1
Version 19.2
Version 20.1
Version 21.1
Oracle
From 18.1 to 18.3
Version 19.1
Version 19.2
Version 20.1
Version 21.1
Configuration D
7 vulnerable
Vulnerable SoftwareAffected Versions
Version 9.3.6
Before 22.1
Version 11.3.2
Oracle
Version 8.58
Version 8.59
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
Configuration E
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 36
Version 37

References (16)

Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
Not Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable

Timeline

No history available yet.