CVE-2014-5191: XSS
Published Aug 7, 2014
·Updated
Cross-site scripting (XSS) vulnerability in the Preview plugin before 4.4.3 in CKEditor allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
4 affected componentsFixes available
composer/ckeditor/ckeditor<4.4.3
4.4.3
CKEditor CKEditor<=4.4.2
CKEditor CKEditor=4.4.0
CKEditor CKEditor=4.4.1
Remediation
Patch Available
Event History
Aug 7, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·11:13 AM
RemedyDescriptionSeverityWeaknessAffected Software
May 17, 2022
Advisory Published
via GitHub·04:08 AM
Frequently Asked Questions
1
What is the severity of CVE-2014-5191?
CVE-2014-5191 is considered a critical vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2014-5191?
To fix CVE-2014-5191, upgrade CKEditor to version 4.4.3 or later.
3
What types of attacks can CVE-2014-5191 enable?
CVE-2014-5191 can enable attackers to inject arbitrary web scripts or HTML into web pages viewed by other users.
4
Which versions of CKEditor are affected by CVE-2014-5191?
The affected versions of CKEditor are all versions before 4.4.3, specifically 4.4.0, 4.4.1, and 4.4.2.
5
Is there any workaround for CVE-2014-5191?
There are no specific workarounds for CVE-2014-5191; the recommended action is to upgrade to a patched version.