Lucene search

K
osvGoogleOSV:GHSA-4M44-5J2G-XF64
HistoryMay 24, 2022 - 5:34 p.m.

Improper Neutralization of Input During Web Page Generation in CKEditor4

2022-05-2417:34:01
Google
osv.dev
6

0.003 Low

EPSS

Percentile

69.8%

A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.

CPENameOperatorVersion
ckeditor4lt4.15.1

0.003 Low

EPSS

Percentile

69.8%