RubySec

Providing security resources for the Ruby community

CVE-2020-9281 (ckeditor): CKEditor 4.0 vulnerability in the HTML Data Processor

CKEditor 4.0 vulnerability in the HTML Data Processor

Published: May 07, 2021

SECURITY IDENTIFIERS

GEM

ckeditor

SEVERITY

CVSS v3.x: 6.1 (Medium)

PATCHED VERSIONS

>= 5.1.2

DESCRIPTION

A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14.0 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).

RELATED