QID 995973
Date Published: 2023-11-20
QID 995973: NodeJs (Npm) Security Update for ckeditor4 (GHSA-hxjc-9j8v-v9pr)
A Cross-Site scripting vulnerability has been found in CKSource CKEditor affecting versions 4.15.1 and earlier. An attacker could send malicious javascript code through the /ckeditor/samples/old/ajax.html file and retrieve an authorized user's information.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-hxjc-9j8v-v9pr for updates and patch information.
Vendor References
- GHSA-hxjc-9j8v-v9pr -
github.com/advisories/GHSA-hxjc-9j8v-v9pr
CVEs related to QID 995973
Software Advisories
| Advisory ID | Software | Component | Link |
|---|