PT-2022-16835 · Unknown+3 · Ckeditor 4+3

Published

2022-03-16

·

Updated

2025-02-06

·

CVE-2022-24728

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions CKEditor 4 versions prior to 4.18.0
Description A vulnerability has been discovered in the core HTML processing module of CKEditor 4, which may affect all plugins used by the editor. This issue allows an attacker to inject malformed HTML, bypassing content sanitization, and potentially executing JavaScript code.
Recommendations For CKEditor 4 versions prior to 4.18.0, update to version 4.18.0 to resolve the issue. At the moment, there are no known workarounds for this vulnerability.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-DRUPAL-2022-24728
BIT-DRUPAL-2022-24729
CVE-2022-24728
DRUPAL-CORE-2022-005
GHSA-4FC4-4P5G-6W89
GHSA-F6RF-9M92-X2HH
USN-7258-1

Affected Products

Ckeditor 4
Debian
Linuxmint
Ubuntu