CVE-2024-37888: The Open Link CKEditor plugin has a cross-site scripting (XSS) vulnerability in open link functionality
The Open Link is a CKEditor plugin, extending context menu with a possibility to open link in a new tab. The vulnerability allowed to execute JavaScript code by abusing link href attribute. It affects all users using the Open Link plugin at version < 1.0.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37888?
CVE-2024-37888 is considered a critical vulnerability due to its potential for executing arbitrary JavaScript code.
How do I fix CVE-2024-37888?
To fix CVE-2024-37888, update the Open Link CKEditor plugin to version 1.0.5 or later.
Who is affected by CVE-2024-37888?
All users utilizing the Open Link plugin for CKEditor versions below 1.0.5 are affected by CVE-2024-37888.
What specific functionality does CVE-2024-37888 exploit?
CVE-2024-37888 exploits the link href attribute within the Open Link plugin to execute unwanted JavaScript.
Is there a workaround for CVE-2024-37888 if I can't update immediately?
Yes, temporarily disabling the Open Link plugin can mitigate the risks associated with CVE-2024-37888.