First published: Wed Apr 18 2018(Updated: )
Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor (in versions 4.5.10 through 4.9.1; fixed in 4.9.2), as used in Drupal 8 before 8.4.7 and 8.5.x before 8.5.2 and other products, allows remote attackers to inject arbitrary web script through a crafted IMG element.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/drupal/core | >=8.0<8.1.0>=8.1.0<8.2.0>=8.2.0<8.3.0>=8.3.0<8.4.0>=8.4<8.4.7>=8.5<8.5.2 | |
composer/drupal/drupal | >=8.0<8.1.0>=8.1.0<8.2.0>=8.2.0<8.3.0>=8.3.0<8.4.0>=8.4<8.4.7>=8.5<8.5.2 | |
Ckeditor Enhanced Image | >=4.5.10<4.9.2 | |
Drupal Drupal | >=8.0.0<8.4.7 | |
Drupal Drupal | >=8.5.0<8.5.2 | |
npm/ckeditor-dev | >=4.5.10<4.9.2 | 4.9.2 |
composer/drupal/core | >=8.5.0<8.5.2 | 8.5.2 |
composer/drupal/core | >=8.0<8.4.7 | 8.4.7 |
composer/drupal/drupal | >=8.5<8.5.2 | 8.5.2 |
composer/drupal/drupal | >=8.0<8.4.7 | 8.4.7 |
>=4.5.10<4.9.2 | ||
>=8.0.0<8.4.7 | ||
>=8.5.0<8.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-9861 is a vulnerability in the Enhanced Image plugin for CKEditor in versions 4.5.10 through 4.9.1, fixed in 4.9.2.
CVE-2018-9861 has a severity value of 6.1 (moderately critical).
The affected software for CVE-2018-9861 includes CKEditor versions 4.5.10 through 4.9.1, Drupal 8 before 8.4.7, and Drupal 8.5.x before 8.5.2.
To fix CVE-2018-9861, update CKEditor to version 4.9.2 and Drupal to versions 8.4.7 or 8.5.2.
The Common Weakness Enumeration (CWE) for CVE-2018-9861 is CWE-79 (Cross-Site Scripting).