CVE-2018-9861 — Cross-site Scripting in Enhanced Image
Severity
6.1MEDIUMNVD
EPSS
0.4%
top 41.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 19
Latest updateMay 14
Description
Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor (in versions 4.5.10 through 4.9.1; fixed in 4.9.2), as used in Drupal 8 before 8.4.7 and 8.5.x before 8.5.2 and other products, allows remote attackers to inject arbitrary web script through a crafted IMG element.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7
Affected Packages5 packages
🔴Vulnerability Details
7OSV▶
CVE-2018-9861: Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor (in versions 4↗2018-04-19
📋Vendor Advisories
3💬Community
3Bugzilla▶
CVE-2018-9861 ckeditor: Cross-site scripting (XSS) vulnerability when using image2 plugin↗2018-04-20
Bugzilla▶
CVE-2018-9861 ckeditor: Cross-site scripting (XSS) vulnerability when using image2 plugin [fedora-all]↗2018-04-20
Bugzilla▶
CVE-2018-9861 drupal8: ckeditor: Cross-site scripting (XSS) vulnerability when using image2 plugin [fedora-all]↗2018-04-20