CVE-2023-4771
published 2023-11-16CVE-2023-4771: A Cross-Site scripting vulnerability has been found in CKSource CKEditor affecting versions 4.15.1 and earlier. An attacker could send malicious javascript…
PriorityP425medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.88%
55.0th percentile
A Cross-Site scripting vulnerability has been found in CKSource CKEditor affecting versions 4.15.1 and earlier. An attacker could send malicious javascript code through the /ckeditor/samples/old/ajax.html file and retrieve an authorized user's information.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ckeditor | ckeditor4 | >= 0 < 4.24.0-lts | 4.24.0-lts |
| cksource | ckeditor | <= 4.15.1 | — |
| debian | ckeditor | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv6.1MEDIUM
vendor_debian6.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
CKEditor cross-site scripting vulnerability in AJAX sample
ghsa·2024-02-07
CVE-2023-4771 [MEDIUM] CWE-79 CKEditor cross-site scripting vulnerability in AJAX sample
CKEditor cross-site scripting vulnerability in AJAX sample
### Affected packages
The vulnerability has been discovered in the AJAX sample available at the `samples/old/ajax.html` file location. All integrators that use that sample in the production code can be affected.
### Impact
A potential vulnerability has been discovered in one of CKEditor's 4 samples that are shipped with production code. The vulnerability allowed to execute JavaScript code by abusing the AJAX sample. It affects all users using the CKEditor 4 at version < 4.24.0-lts where `samples/old/ajax.html` is used in a production environment.
### Patches
The problem has been recognized and patched. The fix will be available in version 4.24.0-lts.
### For more information
Email us at [[email protected]](mailto:security@
OSV
CKEditor cross-site scripting vulnerability in AJAX sample
osv·2024-02-07
CVE-2023-4771 [MEDIUM] CKEditor cross-site scripting vulnerability in AJAX sample
CKEditor cross-site scripting vulnerability in AJAX sample
### Affected packages
The vulnerability has been discovered in the AJAX sample available at the `samples/old/ajax.html` file location. All integrators that use that sample in the production code can be affected.
### Impact
A potential vulnerability has been discovered in one of CKEditor's 4 samples that are shipped with production code. The vulnerability allowed to execute JavaScript code by abusing the AJAX sample. It affects all users using the CKEditor 4 at version < 4.24.0-lts where `samples/old/ajax.html` is used in a production environment.
### Patches
The problem has been recognized and patched. The fix will be available in version 4.24.0-lts.
### For more information
Email us at [[email protected]](mailto:security@
OSV
CVE-2023-4771: A Cross-Site scripting vulnerability has been found in CKSource CKEditor affecting versions 4
osv·2023-11-16·CVSS 6.1
CVE-2023-4771 [MEDIUM] CVE-2023-4771: A Cross-Site scripting vulnerability has been found in CKSource CKEditor affecting versions 4
A Cross-Site scripting vulnerability has been found in CKSource CKEditor affecting versions 4.15.1 and earlier. An attacker could send malicious javascript code through the /ckeditor/samples/old/ajax.html file and retrieve an authorized user's information.
Debian
CVE-2023-4771: ckeditor - A Cross-Site scripting vulnerability has been found in CKSource CKEditor affecti...
vendor_debian·2023·CVSS 6.1
CVE-2023-4771 [MEDIUM] CVE-2023-4771: ckeditor - A Cross-Site scripting vulnerability has been found in CKSource CKEditor affecti...
A Cross-Site scripting vulnerability has been found in CKSource CKEditor affecting versions 4.15.1 and earlier. An attacker could send malicious javascript code through the /ckeditor/samples/old/ajax.html file and retrieve an authorized user's information.
Scope: local
bookworm: open
bullseye: open
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-11-16
Published