ZeroHour

CVE-2020-27193

CVSS 3.1
6.1 medium
EPSS
2%p80
Published
()
Modified
Description

A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.

Vendors
ckeditororacle
Products
ckeditor, agile product lifecycle management, application express, banking party management, banking platform, commerce merchandising, financial services analytical applications infrastructure, jd edwards enterpriseone tools, peoplesoft enterprise peopletools
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.