CVE-2022-24728
Published on: Not Yet Published
Last Modified on: 12/08/2022 10:22:00 PM UTC
Certain versions of Ckeditor from Ckeditor contain the following vulnerability:
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. This problem has been patched in version 4.18.0. There are currently no known workarounds.
- CVE-2022-24728 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
ckeditor - ckeditor4 version < 4.18.0
CVSS3 Score: 5.4 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
CHANGED | LOW | LOW | NONE |
CVSS2 Score: 3.5 - LOW
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | SINGLE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | PARTIAL | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
HTML processing vulnerability allowing to execute JavaScript code · Advisory · ckeditor/ckeditor4 · GitHub | github.com text/html |
![]() |
Code refactoring. · ckeditor/[email protected] · GitHub | github.com text/html |
![]() |
CKEditor 4.18.0 | CKEditor.com | ckeditor.com text/html |
![]() |
[SECURITY] Fedora 36 Update: ckeditor-4.20.0-1.fc36 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org text/html |
![]() |
Access to this page has been denied. | www.drupal.org text/html Inactive LinkNot Archived |
![]() |
Oracle Critical Patch Update Advisory - July 2022 | www.oracle.com text/html |
![]() |
[SECURITY] Fedora 37 Update: ckeditor-4.20.0-1.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org text/html |
![]() |
Related QID Numbers
- 154126 Drupal Core: CKEditor Library Multiple Vulnerabilities (CVE-2022-24728,CVE-2022-24729)
- 283229 Fedora Security Update for ckeditor (FEDORA-2022-b61dfd219b)
- 283475 Fedora Security Update for ckeditor (FEDORA-2022-4c634ee466)
- 730408 Drupal Core CKEDITOR library Cross-Site Scripting (XSS) Vulnerability (SA-CORE-2022-005)
Known Affected Configurations (CPE V2.3)
- cpe:2.3:a:ckeditor:ckeditor:*:*:*:*:*:*:*:*:
- cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*:
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*:
- cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:application_express:*:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:commerce_merchandising:11.3.2:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.1.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.2.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.2.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.0.7.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.0.8.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:financial_services_behavior_detection_platform:*:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:financial_services_trade-based_anti_money_laundering:8.0.7:*:*:*:enterprise:*:*:*:
- cpe:2.3:a:oracle:financial_services_trade-based_anti_money_laundering:8.0.8:*:*:*:enterprise:*:*:*:
- cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-24728 : CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been dis… twitter.com/i/web/status/1… | 2022-03-16 16:09:39 |
![]() |
[email protected] #Vulnérabilité de CKEditor : Cross Site Scripting. vigilance.fr/vulnerabilite/… Références : #CVE-2022-24728.… twitter.com/i/web/status/1… | 2022-03-16 19:09:03 |
![]() |
[email protected] #Vulnerability of CKEditor: Cross Site Scripting. vigilance.fr/vulnerability/… Identifiers: #CVE-2022-24728.… twitter.com/i/web/status/1… | 2022-03-16 19:09:05 |
![]() |
CVE-2022-24728 | 2022-03-16 17:38:36 |