Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Toan Chi Nguyen

Pesquisador deTechlab Corporation
#43428de 53,640
6.1CVSS total
Vulnerabilidades · 1
PT-2018-10304
6.1
2018-05-22
Status Board · Status Board · CVE-2018-11093
**Name of the Vulnerable Software and Affected Versions** CKEditor 5 versions prior to 10.0.1 status-board versions prior to 10.0.1 **Description** A cross-site scripting issue allows remote attackers to inject arbitrary web script through a crafted `href` attribute of a link element. The ` createPreviewButton()` function fails to sanitize the `href` attribute of a created `<a>` tag, which may allow attackers to execute arbitrary JavaScript in a victim's browser. **Recommendations** For CKEditor 5 versions prior to 10.0.1, upgrade to version 10.0.1 or later. For status-board versions prior to 10.0.1, upgrade to version 10.0.1 or later.