PT-2023-26174 · Ckeditor+1 · Ckeditor-Wordcount-Plugin+2

Sybille Peters

·

Publicado

2023-07-10

·

Atualizado

2023-09-15

·

CVE-2023-37905

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ckeditor-wordcount-plugin versions prior to 1.17.12
Description The ckeditor-wordcount-plugin for CKEditor4 is susceptible to cross-site scripting when switching to the source code mode. In default scenarios, exploiting this vulnerability requires a valid backend user account. However, if custom plugins are used on the website frontend, which accept and reflect rich-text content submitted by users, no authentication is required.
Recommendations Update to version 1.17.12 of the ckeditor-wordcount-plugin plugin. As a temporary workaround, consider disabling the plugin until a patch is available. Update to TYPO3 versions 9.5.42 ELTS, 10.4.39 ELTS, 11.5.30 that fix the problem described above.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-37905
GHSA-M8FW-P3CR-6JQC
GHSA-Q9W4-W667-QQJ4

Produtos afetados

Ckeditor4
Typo3
Ckeditor-Wordcount-Plugin