CVE-2024-45400: CKEditor Open Link plugin vulnerable to Cross-site Scripting
ckeditor-plugin-openlink is a plugin for the CKEditor JavaScript text editor that extends the context menu with a possibility to open a link in a new tab. A vulnerability in versions of the plugin prior to 1.0.7 allowed a user to execute JavaScript code by abusing the link href attribute. The fix is available starting with version 1.0.7.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45400?
CVE-2024-45400 has been assigned a critical severity rating due to its potential to allow arbitrary JavaScript execution.
How do I fix CVE-2024-45400?
To fix CVE-2024-45400, update the ckeditor-plugin-openlink to version 1.0.7 or higher.
What versions of the ckeditor-plugin-openlink are affected by CVE-2024-45400?
CVE-2024-45400 affects all versions of the ckeditor-plugin-openlink prior to 1.0.7.
Can CVE-2024-45400 lead to data breaches?
Yes, CVE-2024-45400 can lead to data breaches as it allows the execution of malicious JavaScript code.
What steps should I take if I cannot update to fix CVE-2024-45400?
If you cannot update, immediately disable the ckeditor-plugin-openlink plugin to mitigate the risk associated with CVE-2024-45400.