V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2021-41165
DEB
Medium

CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module…

CVSS
5.4
Medium
EPSS
0.01
p70
Published
2021-01-01
Updated
2021-01-01
Description

CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed comments HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0. The problem has been recognized and patched. The fix will be available in version 4.17.0.

Tags · CWE
XSS
CWE-79
CAPEC-63
CAPEC-85
CAPEC-209
CAPEC-588
CAPEC-591
CAPEC-592
Affected products
CkeditorCkeditorCkeditorCkeditorCkeditorCkeditorCkeditorCkeditorCkeditorCkeditorCkeditorCkeditorCkeditorCkeditorCkeditorCkeditorCkeditorCkeditor3Ckeditor3Ckeditor3
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Timeline
2021-01-01
Published
2021-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: R
Required (R)
Scope
S: C
Changed (C)
Confidentiality Impact
C: L
Low (L)
Integrity Impact
I: L
Low (L)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.015 · p70
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
ckeditorTracked
ckeditorTracked
ckeditorTracked
ckeditorTracked
ckeditorTracked
ckeditorTracked
ckeditorTracked
ckeditorTracked
ckeditorTracked
ckeditorTracked
ckeditorTracked
ckeditorTracked
ckeditorTracked
ckeditorTracked
ckeditorTracked
ckeditorTracked
ckeditorTracked
ckeditor3Tracked
ckeditor3Tracked
ckeditor3Tracked
Showing first 20 of 64
Source databases
DEB
CVE
UBU
Related vulnerabilities