First published: Thu Jan 09 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CKEditor 4 LTS - WYSIWYG HTML editor allows Cross-Site Scripting (XSS).This issue affects CKEditor 4 LTS - WYSIWYG HTML editor: from 1.0.0 before 1.0.1.
Credit: mlhess@drupal.org
Affected Software | Affected Version | How to fix |
---|---|---|
CKEditor 4 LTS | >1.0.0<=1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-13245 is classified as a Critical severity vulnerability due to its potential for Cross-Site Scripting (XSS) attacks.
To fix CVE-2024-13245, upgrade Drupal CKEditor 4 LTS from version 1.0.0 to 1.0.1 or later.
CVE-2024-13245 affects Drupal CKEditor 4 LTS versions from 1.0.0 to earlier than 1.0.1.
The risks of CVE-2024-13245 include unauthorized access to user data and potential site compromise through XSS attacks.
There is no recommended workaround for CVE-2024-13245 other than applying the necessary update to the software.