Description
ckeditor-wordcount-plugin is an open source WordCount Plugin for CKEditor. It has been discovered that the `ckeditor-wordcount-plugin` plugin for CKEditor4 is susceptible to cross-site scripting when switching to the source code mode. This issue has been addressed in version 1.17.12 of the `ckeditor-wordcount-plugin` plugin and users are advised to upgrade. There are no known workarounds for this vulnerability.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2129 | ckeditor-wordcount-plugin is an open source WordCount Plugin for CKEditor. It has been discovered that the `ckeditor-wordcount-plugin` plugin for CKEditor4 is susceptible to cross-site scripting when switching to the source code mode. This issue has been addressed in version 1.17.12 of the `ckeditor-wordcount-plugin` plugin and users are advised to upgrade. There are no known workarounds for this vulnerability. |
Github GHSA |
GHSA-q9w4-w667-qqj4 | ckeditor-wordcount-plugin vulnerable to Cross-site Scripting in Source Mode of Editor |
References
History
Mon, 21 Oct 2024 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-10-21T13:07:15.669Z
Reserved: 2023-07-10T17:51:29.610Z
Link: CVE-2023-37905
Updated: 2024-08-02T17:23:27.702Z
Status : Modified
Published: 2023-07-21T20:15:16.297
Modified: 2024-11-21T08:12:26.300
Link: CVE-2023-37905
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA