Lucene search

K
drupalDrupal Security TeamDRUPAL-SA-CONTRIB-2024-009
HistoryFeb 14, 2024 - 12:00 a.m.

CKEditor 4 LTS - WYSIWYG HTML editor - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024-009

2024-02-1400:00:00
Drupal Security Team
www.drupal.org
6
ckeditor
html editor
security advisory
drupal
cross-site scripting
vulnerability
cdata
xss
update

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

6.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

25.0%

The CKEditor 4 LTS - WYSIWYG HTML editor module uses the CKEditor library for WYSIWYG editing. CKEditor has released a security update that on certain configurations may impact the Drupal module that bundles and integrates this code. The vulnerability is mitigated by the fact it requires: full-page editing mode is enabled or CDATA elements in Advanced Content Filtering configuration (defaults to script and style elements) are enabled. An attacker must have a permission with access to the CKEditor instance. For more information, see CKEditor’s security advisory: CVE-2024-24815: Cross-site scripting (XSS) vulnerability caused by incorrect CDATA detection

Affected configurations

Vulners
Node
drupalckeditor_ltsRange<1.0.1
CPENameOperatorVersion
ckeditor_ltslt1.0.1

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

6.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

25.0%