QID 980090
QID 980090: Nodejs (npm) Security Update for ckeditor4 (GHSA-rgx6-rjj4-c388)
A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!> is mishandled.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-rgx6-rjj4-c388 for updates pertaining to this vulnerability.
Vendor References
- GHSA-rgx6-rjj4-c388 -
github.com/advisories/GHSA-rgx6-rjj4-c388
CVEs related to QID 980090
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-rgx6-rjj4-c388 | ckeditor4 |
|