cbcvebase.
CVE-2020-9281
published 2020-03-07

CVE-2020-9281: A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script…

medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
ckeditorckeditor>= 0 < 4.5.7+dfsg-2ubuntu0.18.04.14.5.7+dfsg-2ubuntu0.18.04.1
ckeditorckeditor>= 0 < 4.12.1+dfsg-1ubuntu0.14.12.1+dfsg-1ubuntu0.1
ckeditorckeditor>= 0 < 4.5.7+dfsg-2ubuntu0.16.04.1~esm14.5.7+dfsg-2ubuntu0.16.04.1~esm1
ckeditorckeditor>= 4.0 < 4.144.14
ckeditorckeditor4>= 0 < 4.14.04.14.0
drupaldrupal>= 8.7.0 < 8.7.128.7.12
drupaldrupal>= 8.8.0 < 8.8.48.8.4
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
fortinetfortianalyzer
fortinetfortianalyzer6.0.0 – 6.2.9
fortinetfortianalyzer6.4.0 – 6.4.8
fortinetfortianalyzer7.0.0 – 7.0.4
fortinetfortimanager
fortinetfortimanager6.0.0 – 6.2.9
fortinetfortimanager6.4.0 – 6.4.8
fortinetfortimanager7.0.0 – 7.0.4
oracleagile_plm
oracleagile_plm
oracleapplication_express< 20.220.2
oraclebanking_enterprise_default_management
oraclebanking_enterprise_default_management
oraclebanking_enterprise_default_management
oraclebanking_enterprise_default_management

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv6.1MEDIUM