Lucene search

K
osvGoogleOSV:GHSA-VCJF-MGCG-JXJQ
HistoryMay 07, 2021 - 4:32 p.m.

CKEditor 4.0 vulnerability in the HTML Data Processor

2021-05-0716:32:17
Google
osv.dev
29
ckeditor
xss
vulnerability
html data processor
remote attackers

EPSS

0.002

Percentile

53.2%

A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14.0 allows remote attackers to inject arbitrary web script through a crafted “protected” comment (with the cke_protected syntax).