PT-2021-6455 · Unknown+3 · Ckeditor 4+3

Published

2021-07-19

·

Updated

2022-03-22

·

CVE-2021-32808

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions CKEditor 4 versions 4.13.0 through 4.16.1
Description A vulnerability has been discovered in the clipboard Widget plugin when used alongside the undo feature in CKEditor 4. This issue allows a user to abuse undo functionality using malformed widget HTML, potentially resulting in the execution of JavaScript code. The problem affects all users of the CKEditor 4 plugins at version 4.13.0 and later.
Recommendations For CKEditor 4 versions 4.13.0 through 4.16.1, update to version 4.16.2 to resolve the issue. As a temporary workaround, consider disabling the undo feature when using the clipboard Widget plugin until a patch is available.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-01665
CVE-2021-32808
GHSA-6226-H7FF-CH6C
USN-5340-1

Affected Products

Ckeditor 4
Debian
Linuxmint
Ubuntu