ZeroHour

CVE-2021-26271

CVSS 3.1
6.5 medium
EPSS
2%p79
Published
()
Modified
Description

It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).

Vendors
ckeditororacle
Products
ckeditor, agile product lifecycle management, application express, financial services analytical applications infrastructure, jd edwards enterpriseone tools, siebel ui framework, webcenter sites
Weakness
CWE-829
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.