PT-2020-5988 · Cksource · Ckeditor
Published
2020-11-09
·
Updated
2022-05-24
·
CVE-2020-27193
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
CKEditor version 4.15.0
Description
A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of the editor inputs. This issue is related to the lack of protection measures for the web page structure, which can be exploited by a remote attacker to conduct cross-site scripting attacks by uploading specially crafted HTML code.
Recommendations
For CKEditor version 4.15.0, consider disabling the Color Dialog plugin until a patch is available to prevent exploitation of the XSS vulnerability. Restrict access to the editor inputs to minimize the risk of arbitrary web script execution. Avoid allowing users to copy and paste crafted HTML code into the editor inputs until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ckeditor