CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. This problem has been patched in version 4.18.0. There are currently no known workarounds.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2022-03-16T00:00:00
Updated: 2024-08-03T04:20:49.856Z
Reserved: 2022-02-10T00:00:00
Link: CVE-2022-24728
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-03-16T16:15:10.907
Modified: 2024-11-21T06:50:57.820
Link: CVE-2022-24728
Redhat
No data.