First published: Tue May 22 2018(Updated: )
Cross-site scripting (XSS) vulnerability in the Link package for CKEditor 5 before 10.0.1 allows remote attackers to inject arbitrary web script through a crafted href attribute of a link (A) element.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ckeditor Ckeditor 5-link | <10.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-11093 is medium with a CVSS score of 6.1.
The Link package for CKEditor 5 before version 10.0.1 is affected by CVE-2018-11093.
Remote attackers can exploit CVE-2018-11093 by injecting arbitrary web script through a crafted href attribute of a link (A) element.
Yes, updating CKEditor 5 to version 10.0.1 or later fixes CVE-2018-11093.
The CWE ID for CVE-2018-11093 is CWE-79 (Cross-Site Scripting).