A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!> is mishandled.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2021-06-09T11:51:00
Updated: 2024-08-03T23:58:23.102Z
Reserved: 2021-06-03T00:00:00
Link: CVE-2021-33829
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-06-09T12:15:07.863
Modified: 2024-11-21T06:09:38.707
Link: CVE-2021-33829
Redhat
No data.