PT-2021-6455 · Unknown+3 · Ckeditor 4+3
Published
2021-07-19
·
Updated
2022-03-22
·
CVE-2021-32808
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
CKEditor 4 versions 4.13.0 through 4.16.1
Description
A vulnerability has been discovered in the clipboard Widget plugin when used alongside the undo feature in CKEditor 4. This issue allows a user to abuse undo functionality using malformed widget HTML, potentially resulting in the execution of JavaScript code. The problem affects all users of the CKEditor 4 plugins at version 4.13.0 and later.
Recommendations
For CKEditor 4 versions 4.13.0 through 4.16.1, update to version 4.16.2 to resolve the issue.
As a temporary workaround, consider disabling the undo feature when using the clipboard Widget plugin until a patch is available.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ckeditor 4
Debian
Linuxmint
Ubuntu