Lucene search

K
osvGoogleOSV:GHSA-Q9W4-W667-QQJ4
HistoryJul 10, 2023 - 9:54 p.m.

ckeditor-wordcount-plugin vulnerable to Cross-site Scripting in Source Mode of Editor

2023-07-1021:54:03
Google
osv.dev
8
ckeditor4
wordcount-plugin
cross-site scripting
source mode
update 1.17.12
typo3 security team

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

0.001 Low

EPSS

Percentile

25.6%

Problem

It has been discovered that the ckeditor-wordcount-plugin plugin for CKEditor4 is susceptible to cross-site scripting when switching to the source code mode.

Solution

Update to version 1.17.12 of the ckeditor-wordcount-plugin plugin.

Credits

  • @sypets for reporting this finding to the TYPO3 Security Team
  • @ohader for fixing the issue on behalf of the TYPO3 Security Team
CPENameOperatorVersion
ckeditor-wordcount-pluginlt1.17.12

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

0.001 Low

EPSS

Percentile

25.6%