QID 980303

QID 980303: Nodejs (npm) Security Update for ckeditor4 (GHSA-vcjf-mgcg-jxjq)

A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to refer to GHSA-vcjf-mgcg-jxjq for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980303

    Software Advisories
    Advisory ID Software Component Link
    GHSA-vcjf-mgcg-jxjq ckeditor4 URL Logo github.com/advisories/GHSA-vcjf-mgcg-jxjq