CVE-2020-27193
published 2020-11-12CVE-2020-27193: A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading…
PriorityP426medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
2.02%
78.7th percentile
A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ckeditor | ckeditor | — | — |
| ckeditor | ckeditor4 | >= 0 < 4.15.1 | 4.15.1 |
| oracle | agile_plm | — | — |
| oracle | agile_plm | — | — |
| oracle | application_express | < 21.1.0.00.01 | 21.1.0.00.01 |
| oracle | banking_party_management | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | commerce_merchandising | — | — |
| oracle | commerce_merchandising | — | — |
| oracle | commerce_merchandising | — | — |
| oracle | commerce_merchandising | — | — |
| oracle | commerce_merchandising | — | — |
| oracle | commerce_merchandising | — | — |
| oracle | financial_services_analytical_applications_infrastructure | — | — |
| oracle | financial_services_analytical_applications_infrastructure | — | — |
| oracle | financial_services_analytical_applications_infrastructure | 8.0.6 – 8.0.9 | — |
| oracle | jd_edwards_enterpriseone_tools | < 9.2.6.0 | 9.2.6.0 |
| oracle | peoplesoft_enterprise_peopletools | — | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_oracle6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Database Server Risk Matrix: Oracle Application Express (CKEditor) — CVE-2020-27193
vendor_oracle·2021-07-15·CVSS 5.4
CVE-2020-27193 [MEDIUM] Oracle Oracle Database Server Risk Matrix: Oracle Application Express (CKEditor) — CVE-2020-27193
Oracle Oracle Database Server Risk Matrix: Oracle Application Express (CKEditor) vulnerability
CVE: CVE-2020-27193
CVSS: 5.4
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Oracle
Oracle Oracle Commerce Risk Matrix: Experience Manager, Business Control Center (CKEditor) — CVE-2020-27193
vendor_oracle·2021-04-15·CVSS 6.1
CVE-2020-27193 [MEDIUM] Oracle Oracle Commerce Risk Matrix: Experience Manager, Business Control Center (CKEditor) — CVE-2020-27193
Oracle Oracle Commerce Risk Matrix: Experience Manager, Business Control Center (CKEditor) vulnerability
CVE: CVE-2020-27193
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
OSV
Improper Neutralization of Input During Web Page Generation in CKEditor4
osv·2022-05-24
CVE-2020-27193 [MEDIUM] Improper Neutralization of Input During Web Page Generation in CKEditor4
Improper Neutralization of Input During Web Page Generation in CKEditor4
A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.
GHSA
Improper Neutralization of Input During Web Page Generation in CKEditor4
ghsa·2022-05-24
CVE-2020-27193 [MEDIUM] CWE-79 Improper Neutralization of Input During Web Page Generation in CKEditor4
Improper Neutralization of Input During Web Page Generation in CKEditor4
A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://ckeditor.com/blog/CKEditor-4.15.1-with-a-security-patch-released/https://ckeditor.com/cke4/release/CKEditor-4.15.1https://ckeditor.com/ckeditor-4/download/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://ckeditor.com/blog/CKEditor-4.15.1-with-a-security-patch-released/https://ckeditor.com/cke4/release/CKEditor-4.15.1https://ckeditor.com/ckeditor-4/download/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2020-11-12
Published