CVE-2018-11093: XSS
Published May 22, 2018
·Updated
Cross-site scripting (XSS) vulnerability in the Link package for CKEditor 5 before 10.0.1 allows remote attackers to inject arbitrary web script through a crafted href attribute of a link (A) element.
Affected Software
1 affected component
CKEditor Ckeditor 5-link Ckeditor 5<10.0.1
Event History
May 22, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-11093?
The severity of CVE-2018-11093 is medium with a CVSS score of 6.1.
2
What software is affected by CVE-2018-11093?
The Link package for CKEditor 5 before version 10.0.1 is affected by CVE-2018-11093.
3
How can remote attackers exploit CVE-2018-11093?
Remote attackers can exploit CVE-2018-11093 by injecting arbitrary web script through a crafted href attribute of a link (A) element.
4
Is there a fix for CVE-2018-11093?
Yes, updating CKEditor 5 to version 10.0.1 or later fixes CVE-2018-11093.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2018-11093?
The CWE ID for CVE-2018-11093 is CWE-79 (Cross-Site Scripting).