ZeroHour

CVE-2021-32808

CVSS 3.1
5.4 medium
EPSS
1%p66
Published
()
Modified
Description

ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malformed widget HTML, which could result in executing JavaScript code. It affects all users using the CKEditor 4 plugins listed above at version >= 4.13.0. The problem has been recognized and patched. The fix will be available in version 4.16.2.

Vendors
ckeditorfedoraprojectoracle
Products
ckeditor, fedora, application express, banking party management, commerce guided search, commerce merchandising, documaker, financial services analytical applications infrastructure, financial services model management and governance, jd edwards enterpriseone tools, peoplesoft enterprise peopletools, siebel ui framework
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.