cbcvebase.
CVE-2022-24728
published 2022-03-16

CVE-2022-24728: CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all…

medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. This problem has been patched in version 4.18.0. There are currently no known workarounds.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
ckeditorckeditor>= 0 < 4.19.0+dfsg-14.19.0+dfsg-1
ckeditorckeditor>= 0 < 4.5.7+dfsg-2ubuntu0.16.04.1~esm24.5.7+dfsg-2ubuntu0.16.04.1~esm2
ckeditorckeditor>= 0 < 4.5.7+dfsg-2ubuntu0.18.04.1+esm14.5.7+dfsg-2ubuntu0.18.04.1+esm1
ckeditorckeditor>= 0 < 4.12.1+dfsg-1ubuntu0.1+esm14.12.1+dfsg-1ubuntu0.1+esm1
ckeditorckeditor>= 0 < 4.16.2+dfsg-1ubuntu0.1~esm14.16.2+dfsg-1ubuntu0.1~esm1
ckeditorckeditor>= 0 < 4.22.1+dfsg1-2ubuntu0.24.04.1~esm14.22.1+dfsg1-2ubuntu0.24.04.1~esm1
ckeditorckeditor>= 4.0 < 4.18.04.18.0
ckeditorckeditor4< 4.18.04.18.0
ckeditorckeditor4>= 0 < 4.18.04.18.0
debianckeditor< ckeditor 4.19.0+dfsg-1 (bookworm)ckeditor 4.19.0+dfsg-1 (bookworm)
debianckeditor3< ckeditor 4.19.0+dfsg-1 (bookworm)ckeditor 4.19.0+dfsg-1 (bookworm)
drupalcore>= 8.0.0 < 9.2.159.2.15
drupalcore>= 9.3.0 < 9.3.89.3.8
drupaldrupal>= 8.0.0 < 9.2.159.2.15
drupaldrupal>= 9.3.0 < 9.3.89.3.8
drupaldrupal_core
fedoraprojectfedora
fedoraprojectfedora
oracleapplication_express< 22.1.122.1.1
oraclecommerce_merchandising
oraclefinancial_services_analytical_applications_infrastructure
oraclefinancial_services_analytical_applications_infrastructure
oraclefinancial_services_analytical_applications_infrastructure
oraclefinancial_services_analytical_applications_infrastructure8.0.7.0.0 – 8.1.0.0.0
oraclefinancial_services_behavior_detection_platform

CVSS provenance

nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
osv5.4MEDIUM