CVE-2020-27193

Severity
6.1MEDIUM
EPSS
1.0%
top 22.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 12
Latest updateMay 24

Description

A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages10 packages

Patches

🔴Vulnerability Details

3
OSV
Improper Neutralization of Input During Web Page Generation in CKEditor42022-05-24
GHSA
Improper Neutralization of Input During Web Page Generation in CKEditor42022-05-24
CVEList
CVE-2020-27193: A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 42020-11-12

📋Vendor Advisories

2
Oracle
Oracle Oracle Database Server Risk Matrix: Oracle Application Express (CKEditor) — CVE-2020-271932021-07-15
Oracle
Oracle Oracle Commerce Risk Matrix: Experience Manager, Business Control Center (CKEditor) — CVE-2020-271932021-04-15