Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-37905
HistoryJul 21, 2023 - 8:15 p.m.

Cross site scripting

2023-07-2120:15:00
PRIOn knowledge base
www.prio-n.com
8
ckeditor4
wordcount plugin
xss
vulnerability
version 1.17.12

0.001 Low

EPSS

Percentile

25.6%

ckeditor-wordcount-plugin is an open source WordCount Plugin for CKEditor. It has been discovered that the ckeditor-wordcount-plugin plugin for CKEditor4 is susceptible to cross-site scripting when switching to the source code mode. This issue has been addressed in version 1.17.12 of the ckeditor-wordcount-plugin plugin and users are advised to upgrade. There are no known workarounds for this vulnerability.

CPENameOperatorVersion
ckeditor-wordcount-pluginlt1.17.12

0.001 Low

EPSS

Percentile

25.6%