CWE
79
Advisory Published

GHSA-w9p3-26fx-5mp3: XSS

First published: Wed May 15 2024(Updated: )

There is an XSS vulnerability in CKEditor, which is used by AlloyEditor, which is used in eZ Platform Admin UI. Scripts can be injected through specially crafted "protected" comments. We are not sure it is exploitable in eZ Platform, but recommend installing it to be on the safe side. It is fixed in CKEditor v4.14, AlloyEditor v2.11.9. It is distributed via Composer, for: ``` eZ Platform v1.13.x: ezsystems/PlatformUIAssetsBundle v4.2.3 (included from ezsystems/PlatformUIBundle v1.13.x) eZ Platform v2.5.13: ezsystems/ezplatform-admin-ui-assets v4.2.1 eZ Platform v3.0.*: ezsystems/ezplatform-admin-ui-assets v5.0.1 eZ Platform v3.1.2: ezsystems/ezplatform-admin-ui-assets v5.1.1 ``` Drafts that are sent to trash become visible in the Review Queue, even for users that were not able to see them before this action. It's not possible to preview them, but their title and review history is displayed. This affects Enterprise Edition only, of which ezplatform-workflow is a part. This security update is distributed via Composer, for ``` eZ Platform EE v2.5.13: ezsystems/ezplatform-workflow v1.1.9 eZ Platform EE v3.1.2: ezsystems/ezplatform-workflow v2.1.1 ```

Affected SoftwareAffected VersionHow to fix
composer/ezsystems/platform-ui-assets-bundle>=4.2.0<4.2.3
4.2.3

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of GHSA-w9p3-26fx-5mp3?

    The GHSA-w9p3-26fx-5mp3 is classified as a Cross-Site Scripting (XSS) vulnerability, which can pose a significant risk if exploited.

  • How do I fix GHSA-w9p3-26fx-5mp3?

    To fix GHSA-w9p3-26fx-5mp3, update the affected package ezsystems/platform-ui-assets-bundle to version 4.2.3 or later.

  • What causes the GHSA-w9p3-26fx-5mp3 vulnerability?

    The GHSA-w9p3-26fx-5mp3 vulnerability is caused by the ability to inject scripts through specially crafted protected comments in CKEditor.

  • Who is affected by GHSA-w9p3-26fx-5mp3?

    Users of CKEditor within the AlloyEditor framework in eZ Platform Admin UI are potentially affected by GHSA-w9p3-26fx-5mp3.

  • Can GHSA-w9p3-26fx-5mp3 be exploited in eZ Platform?

    It is currently unclear if GHSA-w9p3-26fx-5mp3 is exploitable in eZ Platform, but it is recommended to apply the fix as a precaution.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203