QID 980303
QID 980303: Nodejs (npm) Security Update for ckeditor4 (GHSA-vcjf-mgcg-jxjq)
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-vcjf-mgcg-jxjq for updates pertaining to this vulnerability.
Vendor References
- GHSA-vcjf-mgcg-jxjq -
github.com/advisories/GHSA-vcjf-mgcg-jxjq
CVEs related to QID 980303
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-vcjf-mgcg-jxjq | ckeditor4 |
|