First published: Thu Nov 12 2020(Updated: )
A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ckeditor Ckeditor | =4.15.0 | |
Oracle Agile PLM | =9.3.5 | |
Oracle Agile PLM | =9.3.6 | |
Oracle Application Express | <21.1.0.00.01 | |
Oracle Banking Party Management | =2.7.0 | |
Oracle Banking Platform | =2.4.0 | |
Oracle Banking Platform | =2.7.0 | |
Oracle Banking Platform | =2.7.1 | |
Oracle Banking Platform | =2.8.0 | |
Oracle Banking Platform | =2.9.0 | |
Oracle Commerce Merchandising | =11.0.0 | |
Oracle Commerce Merchandising | =11.1.0 | |
Oracle Commerce Merchandising | =11.2.0 | |
Oracle Commerce Merchandising | =11.3.0 | |
Oracle Commerce Merchandising | =11.3.1 | |
Oracle Commerce Merchandising | =11.3.2 | |
Oracle Financial Services Analytical Applications Infrastructure | >=8.0.6<=8.0.9 | |
Oracle Financial Services Analytical Applications Infrastructure | =8.1.0 | |
Oracle Financial Services Analytical Applications Infrastructure | =8.1.1 | |
Oracle Jd Edwards Enterpriseone Tools | <9.2.6.0 | |
Oracle PeopleSoft Enterprise PeopleTools | =8.56 | |
Oracle PeopleSoft Enterprise PeopleTools | =8.57 | |
Oracle PeopleSoft Enterprise PeopleTools | =8.58 | |
IBM IBM® Engineering Requirements Management DOORS | <=9.7.2.7 | |
IBM IBM® Engineering Requirements Management DOORS Web Access | <=9.7.2.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-27193.
CVE-2020-27193 has a severity of 6.1, which is considered medium.
The Color Dialog plugin for CKEditor version 4.15.0 is affected by CVE-2020-27193.
Remote attackers can exploit CVE-2020-27193 by persuading a user to copy and paste crafted HTML code into one of the editor inputs.
Yes, a security patch has been released for CVE-2020-27193. It is recommended to update to CKEditor version 4.15.1.