CVE-2024-24815
published 2024-02-07CVE-2024-24815: CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been discovered in the core HTML parsing module…
PriorityP425medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.71%
49.5th percentile
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been discovered in the core HTML parsing module in versions of CKEditor4 prior to 4.24.0-lts. It may affect all editor instances that enabled full-page editing mode or enabled CDATA elements in Advanced Content Filtering configuration (defaults to `script` and `style` elements). The vulnerability allows attackers to inject malformed HTML content bypassing Advanced Content Filtering mechanism, which could result in executing JavaScript code. An attacker could abuse faulty CDATA content detection and use it to prepare an intentional attack on the editor. A fix is available in version 4.24.0-lts.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ckeditor | ckeditor | >= 0 < 4.24.0 | 4.24.0 |
| ckeditor | ckeditor | >= 0 < 4.5.7+dfsg-2ubuntu0.16.04.1~esm2 | 4.5.7+dfsg-2ubuntu0.16.04.1~esm2 |
| ckeditor | ckeditor | >= 0 < 4.5.7+dfsg-2ubuntu0.18.04.1+esm1 | 4.5.7+dfsg-2ubuntu0.18.04.1+esm1 |
| ckeditor | ckeditor | >= 0 < 4.12.1+dfsg-1ubuntu0.1+esm1 | 4.12.1+dfsg-1ubuntu0.1+esm1 |
| ckeditor | ckeditor | >= 0 < 4.16.2+dfsg-1ubuntu0.1~esm1 | 4.16.2+dfsg-1ubuntu0.1~esm1 |
| ckeditor | ckeditor | >= 0 < 4.22.1+dfsg1-2ubuntu0.24.04.1~esm1 | 4.22.1+dfsg1-2ubuntu0.24.04.1~esm1 |
| ckeditor | ckeditor | >= 4.0 < 4.24.0 | 4.24.0 |
| ckeditor | ckeditor4 | < 4.24.0-lts | 4.24.0-lts |
| ckeditor | ckeditor4 | >= 0 < 4.24.0-lts | 4.24.0-lts |
| debian | ckeditor | — | — |
| debian | ckeditor3 | — | — |
| drupal | ckeditor_4_lts | — | — |
| drupal | ckeditor_lts | >= 1.0.0 < 1.0.1 | 1.0.1 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_ubuntu5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
CKEditor vulnerabilities
vendor_ubuntu·2025-02-06·CVSS 5.4
CVE-2024-24816 [MEDIUM] CKEditor vulnerabilities
Title: CKEditor vulnerabilities
Summary: Several security issues were fixed in CKEditor.
Kevin Backhouse discovered that CKEditor did not properly sanitize HTML
content. An attacker could possibly use this issue to perform cross site
scripting and obtain sensitive information. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2022-24728)
It was discovered that CKEditor did not properly handle the creation of
editor instances in the Iframe Dialog and Media Embed packages. An
attacker could possibly use this issue to perform cross site scripting
and obtain sensitive information. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2023-28439)
It was discovered that CKEditor did not
Drupal
CKEditor 4 LTS - WYSIWYG HTML editor - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024-009
vendor_drupal·2024-02-14·CVSS 6.1
CVE-2024-13245 [MEDIUM] CKEditor 4 LTS - WYSIWYG HTML editor - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024-009
Title: CKEditor 4 LTS - WYSIWYG HTML editor - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024-009
Vulnerability Type: Cross Site Scripting
Description: The CKEditor 4 LTS - WYSIWYG HTML editor module uses the CKEditor library for WYSIWYG editing. CKEditor has released a security update that on certain configurations may impact the Drupal module that bundles and integrates this code. The vulnerability is mitigated by the fact it requires: full-page editing mode is enabled or CDATA elements in Advanced Content Filtering configuration (defaults to script and style elements) are enabled. An attacker must have a permission with access to the CKEditor instance. For more information, see CKEditor's security advisory: CVE-2024-24815 : Cross-site scripting (XSS) vulnerability caused
Debian
CVE-2024-24815: ckeditor - CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-si...
vendor_debian·2024·CVSS 6.1
CVE-2024-24815 [MEDIUM] CVE-2024-24815: ckeditor - CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-si...
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been discovered in the core HTML parsing module in versions of CKEditor4 prior to 4.24.0-lts. It may affect all editor instances that enabled full-page editing mode or enabled CDATA elements in Advanced Content Filtering configuration (defaults to `script` and `style` elements). The vulnerability allows attackers to inject malformed HTML content bypassing Advanced Content Filtering mechanism, which could result in executing JavaScript code. An attacker could abuse faulty CDATA content detection and use it to prepare an intentional attack on the editor. A fix is available in version 4.24.0-lts.
Scope: local
bookworm: open
bullseye: open
OSV
ckeditor vulnerabilities
osv·2025-02-06·CVSS 5.4
CVE-2022-24728 [MEDIUM] ckeditor vulnerabilities
ckeditor vulnerabilities
Kevin Backhouse discovered that CKEditor did not properly sanitize HTML
content. An attacker could possibly use this issue to perform cross site
scripting and obtain sensitive information. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2022-24728)
It was discovered that CKEditor did not properly handle the creation of
editor instances in the Iframe Dialog and Media Embed packages. An
attacker could possibly use this issue to perform cross site scripting
and obtain sensitive information. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2023-28439)
It was discovered that CKEditor did not properly handle parsing HTML
content. An attacker could possibly
OSV
CVE-2024-13245: The CKEditor 4 LTS - WYSIWYG HTML editor module uses the CKEditor library for WYSIWYG editing
osv·2024-02-14·CVSS 6.1
CVE-2024-13245 [MEDIUM] CVE-2024-13245: The CKEditor 4 LTS - WYSIWYG HTML editor module uses the CKEditor library for WYSIWYG editing
The CKEditor 4 LTS - WYSIWYG HTML editor module uses the CKEditor library for WYSIWYG editing. CKEditor has released a [security update](https://ckeditor.com/cke4/release/CKEditor-4.24.0-LTS) that on certain configurations may impact the Drupal module that bundles and integrates this code.
The vulnerability is mitigated by the fact it requires:
1. [full-page editing](https://ckeditor.com/docs/ckeditor4/latest/features/fullpage.html) mode is enabled
2. or CDATA elements in Advanced Content Filtering configuration (defaults to script and style elements) are enabled.
3. An attacker must have a permission with access to the CKEditor instance.
For more information, see CKEditor's security advisory:
[CVE-2024-24815](https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-fq6h-4g8v-qqvm
OSV
CVE-2024-24815: CKEditor4 is an open source what-you-see-is-what-you-get HTML editor
osv·2024-02-07·CVSS 6.1
CVE-2024-24815 [MEDIUM] CVE-2024-24815: CKEditor4 is an open source what-you-see-is-what-you-get HTML editor
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been discovered in the core HTML parsing module in versions of CKEditor4 prior to 4.24.0-lts. It may affect all editor instances that enabled full-page editing mode or enabled CDATA elements in Advanced Content Filtering configuration (defaults to `script` and `style` elements). The vulnerability allows attackers to inject malformed HTML content bypassing Advanced Content Filtering mechanism, which could result in executing JavaScript code. An attacker could abuse faulty CDATA content detection and use it to prepare an intentional attack on the editor. A fix is available in version 4.24.0-lts.
OSV
CKEditor4 Cross-site Scripting vulnerability caused by incorrect CDATA detection
osv·2024-02-07
CVE-2024-24815 [MEDIUM] CKEditor4 Cross-site Scripting vulnerability caused by incorrect CDATA detection
CKEditor4 Cross-site Scripting vulnerability caused by incorrect CDATA detection
### Affected packages
The vulnerability has been discovered in the core HTML parsing module and may affect all editor instances that:
* Enabled [full-page editing](https://ckeditor.com/docs/ckeditor4/latest/features/fullpage.html) mode,
* or enabled [CDATA](https://ckeditor.com/docs/ckeditor4/latest/api/CKEDITOR_dtd.html#property-S-cdata) elements in [Advanced Content Filtering](https://ckeditor.com/docs/ckeditor4/latest/guide/dev_advanced_content_filter.html) configuration (defaults to `script` and `style` elements).
### Impact
A potential vulnerability has been discovered in CKEditor 4 HTML processing core module. The vulnerability allowed to inject malformed HTML content bypassing Advanced Content Filter
GHSA
CKEditor4 Cross-site Scripting vulnerability caused by incorrect CDATA detection
ghsa·2024-02-07
CVE-2024-24815 [MEDIUM] CWE-79 CKEditor4 Cross-site Scripting vulnerability caused by incorrect CDATA detection
CKEditor4 Cross-site Scripting vulnerability caused by incorrect CDATA detection
### Affected packages
The vulnerability has been discovered in the core HTML parsing module and may affect all editor instances that:
* Enabled [full-page editing](https://ckeditor.com/docs/ckeditor4/latest/features/fullpage.html) mode,
* or enabled [CDATA](https://ckeditor.com/docs/ckeditor4/latest/api/CKEDITOR_dtd.html#property-S-cdata) elements in [Advanced Content Filtering](https://ckeditor.com/docs/ckeditor4/latest/guide/dev_advanced_content_filter.html) configuration (defaults to `script` and `style` elements).
### Impact
A potential vulnerability has been discovered in CKEditor 4 HTML processing core module. The vulnerability allowed to inject malformed HTML content bypassing Advanced Content Filter
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://ckeditor.com/docs/ckeditor4/latest/api/CKEDITOR_dtd.html#property-S-cdatahttps://ckeditor.com/docs/ckeditor4/latest/features/fullpage.htmlhttps://ckeditor.com/docs/ckeditor4/latest/guide/dev_advanced_content_filter.htmlhttps://github.com/ckeditor/ckeditor4/commit/8ed1a3c93d0ae5f49f4ecff5738ab8a2972194cbhttps://github.com/ckeditor/ckeditor4/security/advisories/GHSA-fq6h-4g8v-qqvmhttps://www.drupal.org/sa-contrib-2024-009https://ckeditor.com/docs/ckeditor4/latest/api/CKEDITOR_dtd.html#property-S-cdatahttps://ckeditor.com/docs/ckeditor4/latest/features/fullpage.htmlhttps://ckeditor.com/docs/ckeditor4/latest/guide/dev_advanced_content_filter.htmlhttps://github.com/ckeditor/ckeditor4/commit/8ed1a3c93d0ae5f49f4ecff5738ab8a2972194cbhttps://github.com/ckeditor/ckeditor4/security/advisories/GHSA-fq6h-4g8v-qqvmhttps://www.drupal.org/sa-contrib-2024-009
2024-02-07
Published