Lucene search

K
osvGoogleOSV:CVE-2020-9440
HistoryMar 10, 2020 - 5:15 p.m.

CVE-2020-9440

2020-03-1017:15:13
Google
osv.dev
10

AI Score

5.5

Confidence

High

EPSS

0.003

Percentile

67.9%

A cross-site scripting (XSS) vulnerability in the WSC plugin through 5.5.7.5 for CKEditor 4 allows remote attackers to run arbitrary web script inside an IFRAME element by injecting a crafted HTML element into the editor.

AI Score

5.5

Confidence

High

EPSS

0.003

Percentile

67.9%