CVE-2020-9281
—CVSS 3.1
6.1 medium
EPSS
4%p91
Published
()
Modified
Description
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
- Vendors
- ckeditorfedoraprojectdrupaloracle
- Products
- ckeditor, fedora, drupal, agile product lifecycle management, application express, jd edwards enterpriseone tools, peoplesoft enterprise peopletools, siebel apps - customer order management, webcenter portal, banking enterprise default management, banking enterprise default managment
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.