Premium Software CLEditor 1.4.5 and earlier is affected by: Cross Site Scripting (XSS). The impact is: An attacker might be able to inject arbitrary html and script code into the web site. The component is: jQuery plug-in. The attack vector is: the victim must open a crafted href attribute of a link (A) element.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-0593 Premium Software CLEditor 1.4.5 and earlier is affected by: Cross Site Scripting (XSS). The impact is: An attacker might be able to inject arbitrary html and script code into the web site. The component is: jQuery plug-in. The attack vector is: the victim must open a crafted href attribute of a link (A) element.
Github GHSA Github GHSA GHSA-hh56-x62g-gvhc Cross-site scripting in CLEditor
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: dwf

Published:

Updated: 2024-08-05T03:07:17.997Z

Reserved: 2019-03-20T00:00:00

Link: CVE-2019-1010113

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-07-19T16:15:12.180

Modified: 2024-11-21T04:17:58.730

Link: CVE-2019-1010113

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses