CVE-2018-9861: XSS
Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor (in versions 4.5.10 through 4.9.1; fixed in 4.9.2), as used in Drupal 8 before 8.4.7 and 8.5.x before 8.5.2 and other products, allows remote attackers to inject arbitrary web script through a crafted IMG element.
Other sources
Moderately critical - Cross Site Scripting
The Enhanced Image (aka image2) plugin for CKEditor in versions 4.5.10 through 4.9.1; fixed in 4.9.2, and as used in Drupal 8 before 8.4.7 and 8.5.x before 8.5.2 and other products, is vulnerable to cross-site scripting because it allows remote attackers to inject arbitrary web script through a crafted IMG element.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/drupal/drupalto a version that resolves this vulnerability.Fixed in 8.5.2 - Upgrade
Upgrade
composer/drupal/drupalto a version that resolves this vulnerability.Fixed in 8.4.7 - Upgrade
Upgrade
npm/ckeditor-devto a version that resolves this vulnerability.Fixed in 4.9.2 - Upgrade
Upgrade
composer/drupal/coreto a version that resolves this vulnerability.Fixed in 8.5.2 - Upgrade
Upgrade
composer/drupal/coreto a version that resolves this vulnerability.Fixed in 8.4.7 - Upgrade
Upgrade
CKEditor Enhanced Image (image2) pluginto a version that resolves this vulnerability.Fixed in 4.9.2 - Upgrade
Upgrade
Drupal 8 (where CKEditor image2 plugin is used)to a version that resolves this vulnerability.Fixed in 8.4.7 - Upgrade
Upgrade
Drupal 8 (where CKEditor image2 plugin is used)to a version that resolves this vulnerability.Fixed in 8.5.2
Event History
Frequently Asked Questions
What is CVE-2018-9861?
CVE-2018-9861 is a vulnerability in the Enhanced Image plugin for CKEditor in versions 4.5.10 through 4.9.1, fixed in 4.9.2.
How severe is CVE-2018-9861?
CVE-2018-9861 has a severity value of 6.1 (moderately critical).
What is the affected software for CVE-2018-9861?
The affected software for CVE-2018-9861 includes CKEditor versions 4.5.10 through 4.9.1, Drupal 8 before 8.4.7, and Drupal 8.5.x before 8.5.2.
How do I fix CVE-2018-9861?
To fix CVE-2018-9861, update CKEditor to version 4.9.2 and Drupal to versions 8.4.7 or 8.5.2.
What is the Common Weakness Enumeration (CWE) for CVE-2018-9861?
The Common Weakness Enumeration (CWE) for CVE-2018-9861 is CWE-79 (Cross-Site Scripting).