First published: Thu Nov 16 2023(Updated: )
A Cross-Site scripting vulnerability has been found in CKSource CKEditor affecting versions 4.15.1 and earlier. An attacker could send malicious javascript code through the /`ckeditor/samples/old/ajax.html` file and retrieve an authorized user's information.
Affected Software | Affected Version | How to fix |
---|---|---|
npm/ckeditor4 | <=4.15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this CKEditor vulnerability is GHSA-hxjc-9j8v-v9pr.
The severity of the CKEditor vulnerability (GHSA-hxjc-9j8v-v9pr) is medium.
The CKEditor vulnerability (GHSA-hxjc-9j8v-v9pr) affects versions 4.15.1 and earlier of CKSource CKEditor.
An attacker can exploit the CKEditor vulnerability (GHSA-hxjc-9j8v-v9pr) by sending malicious JavaScript code through the /ckeditor/samples/old/ajax.html file to retrieve an authorized user's information.
You can find more information about the CKEditor vulnerability (GHSA-hxjc-9j8v-v9pr) at the following references: [CVE-2023-4771](https://nvd.nist.gov/vuln/detail/CVE-2023-4771), [INCIBE CERT](https://www.incibe.es/en/incibe-cert/notices/aviso/cross-site-scripting-vulnerability-cksource-ckeditor), [GitHub Advisory](https://github.com/advisories/GHSA-hxjc-9j8v-v9pr).