Skip to content

Ckeditor XSS Vulnerability

Moderate severity GitHub Reviewed Published Nov 21, 2018 to the GitHub Advisory Database • Updated Feb 5, 2024

Package

npm ckeditor (npm)

Affected versions

< 4.11.0

Patched versions

4.11.0
composer typo3/cms (Composer)
>= 8.0.0, < 8.7.21
>= 9.0.0, < 9.5.2
8.7.21
9.5.2
composer typo3/cms-core (Composer)
>= 8.0.0, < 8.7.21
>= 9.0.0, < 9.5.2
8.7.21
9.5.2

Description

CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste. It was possible to execute XSS inside the CKEditor source area after persuading the victim to: (i) switch CKEditor to source mode, then (ii) paste a specially crafted HTML code, prepared by the attacker, into the opened CKEditor source area, and (iii) switch back to WYSIWYG mode. Although this is an unlikely scenario, it is recommended to upgrade to the latest editor version.

References

Published to the GitHub Advisory Database Nov 21, 2018
Reviewed Jun 16, 2020
Last updated Feb 5, 2024

Severity

Moderate
6.1
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Weaknesses

CVE ID

CVE-2018-17960

GHSA ID

GHSA-g68x-vvqq-pvw3

Source code

No known source code
Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.