Lucene search

K
osvGoogleOSV:CVE-2021-26271
HistoryJan 26, 2021 - 9:15 p.m.

CVE-2021-26271

2021-01-2621:15:12
Google
osv.dev
9
redos attack
ckeditor 4
persuading victim
crafted text
styles input
advanced tab
dialogs plugin

AI Score

6.9

Confidence

Low

EPSS

0.001

Percentile

51.0%

It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).

AI Score

6.9

Confidence

Low

EPSS

0.001

Percentile

51.0%