PT-2021-21815 · Unknown+3 · Ckeditor 4+3
Victor Rodriguez
·
Published
2021-08-12
·
Updated
2022-03-23
·
CVE-2021-37695
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
CKEditor 4 versions prior to 4.16.2
Description
A potential vulnerability has been discovered in the CKEditor 4 [Fake Objects] package, allowing the injection of malformed Fake Objects HTML, which could result in executing JavaScript code. This issue affects all users using the CKEditor 4 plugins listed, including [Fake Objects], [Link], [Flash], [Iframe], [Forms], and [Page Break], at versions prior to 4.16.2.
Recommendations
For CKEditor 4 versions prior to 4.16.2, update to version 4.16.2 to resolve the issue. As a temporary workaround, consider disabling the use of the [Fake Objects] plugin until the patch is applied. Restrict access to the affected plugins to minimize the risk of exploitation. Avoid using the affected plugins in the CKEditor 4 package until the issue is resolved.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ckeditor 4
Debian
Linuxmint
Ubuntu