PT-2021-6875 · Unknown+1 · Ckeditor 4+1

Published

2021-11-17

·

Updated

2024-03-06

·

CVE-2021-41164

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions CKEditor 4 versions prior to 4.17.0
Description The issue is related to the Advanced Content Filter (ACF) module in CKEditor 4, which fails to properly protect the structure of web pages. This allows a remote attacker to bypass existing access restriction policies for HTML elements. The vulnerability enables the injection of malformed HTML, bypassing content sanitization, and could result in the execution of JavaScript code.
Recommendations For versions prior to 4.17.0, update to version 4.17.0 to resolve the issue. As a temporary workaround, consider restricting the use of the Advanced Content Filter (ACF) module until the patch is applied. Avoid using the CKEditor 4 at versions less than 4.17.0 to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2022-02391
BIT-DRUPAL-2021-41164
CVE-2021-41164
GHSA-PVMX-G8H5-CPRJ

Affected Products

Ckeditor 4
Debian