CVE-2022-24728
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD
Description
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. This problem has been patched in version 4.18.0. There are currently no known workarounds.
Affected (18)
Products: Ckeditor: Ckeditor · Drupal: Drupal · Oracle: Application Express, Commerce Merchandising, Financial Services Analytical Applications Infrastructure, Financial Services Behavior Detection Platform, Financial Services Trade Based Anti Money Laundering, Peoplesoft Enterprise Peopletools · +1 more
Show all products
Ckeditor: Ckeditor · Drupal: Drupal · Oracle: Application Express, Commerce Merchandising, Financial Services Analytical Applications Infrastructure, Financial Services Behavior Detection Platform, Financial Services Trade Based Anti Money Laundering, Peoplesoft Enterprise Peopletools · Fedoraproject: Fedora
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 22.1.1 | |
| Version 11.3.2 | |
| From 8.0.7.0.0 to 8.1.0.0.0 | |
| From 8.1.1.0 to 8.1.2.1 | |
| Version 8.0.7 | |
| Version 8.58 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 36 |
References (14)
Source: security-advisories@github.com
Release NotesVendor Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
Source: security-advisories@github.com
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.