PT-2025-2084 · Unknown · Ckeditor 4 Lts

Catch

+6

·

Published

2025-01-09

·

Updated

2025-07-07

·

CVE-2024-13245

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions CKEditor 4 LTS - WYSIWYG HTML editor versions 1.0.0 through 1.0.0
Description The issue is related to improper neutralization of input during web page generation, allowing Cross-Site Scripting (XSS). This enables attackers to inject malicious scripts into websites, potentially leading to unauthorized access or control.
Recommendations For CKEditor 4 LTS - WYSIWYG HTML editor version 1.0.0, update to version 1.0.1 to resolve the issue.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-13245
DRUPAL-CONTRIB-2024-009

Affected Products

Ckeditor 4 Lts