First published: Wed Nov 14 2018(Updated: )
CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/typo3/cms | >=8.0.0<8.7.21>=9.0.0<9.5.2 | |
composer/typo3/cms-core | >=8.0.0<8.7.21>=9.0.0<9.5.2 | |
Ckeditor Ckeditor | >=4.0<4.11.0 | |
composer/typo3/cms | >=9.0.0<9.5.2 | 9.5.2 |
composer/typo3/cms | >=8.0.0<8.7.21 | 8.7.21 |
composer/typo3/cms-core | >=9.0.0<9.5.2 | 9.5.2 |
composer/typo3/cms-core | >=8.0.0<8.7.21 | 8.7.21 |
npm/ckeditor | <4.11.0 | 4.11.0 |
IBM IBM® Engineering Requirements Management DOORS | <=9.7.2.7 | |
IBM IBM® Engineering Requirements Management DOORS Web Access | <=9.7.2.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17960 is a vulnerability in CKEditor 4.x that allows user-assisted cross-site scripting (XSS) attacks.
CVE-2018-17960 allows an attacker to execute XSS inside the CKEditor source area by persuading the victim to switch to source mode and paste a specially crafted HTML code.
CVE-2018-17960 affects TYPO3 CMS versions 8.0.0 to 8.7.21 and 9.0.0 to 9.5.2, as well as CKEditor versions up to 4.11.0.
CVE-2018-17960 has a severity rating of 6.1 (medium).
To fix CVE-2018-17960, you should update CKEditor to version 4.11.0 or later.