CVE-2024-24816
published 2024-02-07CVE-2024-24816: CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability vulnerability has been discovered in versions prior…
PriorityP427medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.65%
74.0th percentile
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability vulnerability has been discovered in versions prior to 4.24.0-lts in samples that use the `preview` feature. All integrators that use these samples in the production code can be affected. The vulnerability allows an attacker to execute JavaScript code by abusing the misconfigured preview feature. It affects all users using the CKEditor 4 at version < 4.24.0-lts with affected samples used in a production environment. A fix is available in version 4.24.0-lts.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ckeditor | ckeditor | >= 0 < 4.5.7+dfsg-2ubuntu0.16.04.1~esm2 | 4.5.7+dfsg-2ubuntu0.16.04.1~esm2 |
| ckeditor | ckeditor | >= 0 < 4.5.7+dfsg-2ubuntu0.18.04.1+esm1 | 4.5.7+dfsg-2ubuntu0.18.04.1+esm1 |
| ckeditor | ckeditor | >= 0 < 4.12.1+dfsg-1ubuntu0.1+esm1 | 4.12.1+dfsg-1ubuntu0.1+esm1 |
| ckeditor | ckeditor | >= 0 < 4.16.2+dfsg-1ubuntu0.1~esm1 | 4.16.2+dfsg-1ubuntu0.1~esm1 |
| ckeditor | ckeditor | >= 0 < 4.22.1+dfsg1-2ubuntu0.24.04.1~esm1 | 4.22.1+dfsg1-2ubuntu0.24.04.1~esm1 |
| ckeditor | ckeditor | >= 4.0 < 4.24.0 | 4.24.0 |
| ckeditor | ckeditor4 | < 4.24.0-lts | 4.24.0-lts |
| ckeditor | ckeditor4 | >= 0 < 4.24.0-lts | 4.24.0-lts |
| debian | ckeditor | — | — |
| debian | ckeditor3 | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_oracle6.1MEDIUM
vendor_ubuntu5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
CKEditor vulnerabilities
vendor_ubuntu·2025-02-06·CVSS 5.4
CVE-2024-24816 [MEDIUM] CKEditor vulnerabilities
Title: CKEditor vulnerabilities
Summary: Several security issues were fixed in CKEditor.
Kevin Backhouse discovered that CKEditor did not properly sanitize HTML
content. An attacker could possibly use this issue to perform cross site
scripting and obtain sensitive information. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2022-24728)
It was discovered that CKEditor did not properly handle the creation of
editor instances in the Iframe Dialog and Media Embed packages. An
attacker could possibly use this issue to perform cross site scripting
and obtain sensitive information. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2023-28439)
It was discovered that CKEditor did not
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Web UI (CKEditor) — CVE-2024-24816
vendor_oracle·2024-07-15·CVSS 6.1
CVE-2024-24816 [MEDIUM] Oracle Oracle Financial Services Applications Risk Matrix: Web UI (CKEditor) — CVE-2024-24816
Oracle Oracle Financial Services Applications Risk Matrix: Web UI (CKEditor) vulnerability
CVE: CVE-2024-24816
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2024 (JUL 2024)
Oracle
Oracle Oracle Insurance Applications Risk Matrix: Enterprise Edition (CKEditor) — CVE-2024-24816
vendor_oracle·2024-04-15·CVSS 6.1
CVE-2024-24816 [MEDIUM] Oracle Oracle Insurance Applications Risk Matrix: Enterprise Edition (CKEditor) — CVE-2024-24816
Oracle Oracle Insurance Applications Risk Matrix: Enterprise Edition (CKEditor) vulnerability
CVE: CVE-2024-24816
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2024 (APR 2024)
Debian
CVE-2024-24816: ckeditor - CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-si...
vendor_debian·2024·CVSS 6.1
CVE-2024-24816 [MEDIUM] CVE-2024-24816: ckeditor - CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-si...
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability vulnerability has been discovered in versions prior to 4.24.0-lts in samples that use the `preview` feature. All integrators that use these samples in the production code can be affected. The vulnerability allows an attacker to execute JavaScript code by abusing the misconfigured preview feature. It affects all users using the CKEditor 4 at version < 4.24.0-lts with affected samples used in a production environment. A fix is available in version 4.24.0-lts.
Scope: local
bookworm: open
bullseye: open
OSV
ckeditor vulnerabilities
osv·2025-02-06·CVSS 5.4
CVE-2022-24728 [MEDIUM] ckeditor vulnerabilities
ckeditor vulnerabilities
Kevin Backhouse discovered that CKEditor did not properly sanitize HTML
content. An attacker could possibly use this issue to perform cross site
scripting and obtain sensitive information. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2022-24728)
It was discovered that CKEditor did not properly handle the creation of
editor instances in the Iframe Dialog and Media Embed packages. An
attacker could possibly use this issue to perform cross site scripting
and obtain sensitive information. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2023-28439)
It was discovered that CKEditor did not properly handle parsing HTML
content. An attacker could possibly
OSV
CVE-2024-24816: CKEditor4 is an open source what-you-see-is-what-you-get HTML editor
osv·2024-02-07·CVSS 6.1
CVE-2024-24816 [MEDIUM] CVE-2024-24816: CKEditor4 is an open source what-you-see-is-what-you-get HTML editor
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability vulnerability has been discovered in versions prior to 4.24.0-lts in samples that use the `preview` feature. All integrators that use these samples in the production code can be affected. The vulnerability allows an attacker to execute JavaScript code by abusing the misconfigured preview feature. It affects all users using the CKEditor 4 at version < 4.24.0-lts with affected samples used in a production environment. A fix is available in version 4.24.0-lts.
OSV
CKEditor4 Cross-site Scripting vulnerability in samples with enabled the preview feature
osv·2024-02-07
CVE-2024-24816 [MEDIUM] CKEditor4 Cross-site Scripting vulnerability in samples with enabled the preview feature
CKEditor4 Cross-site Scripting vulnerability in samples with enabled the preview feature
### Affected packages
The vulnerability has been discovered in the samples that use the [preview](https://ckeditor.com/cke4/addon/preview) feature:
* `samples/old/**/*.html`
* `plugins/[plugin name]/samples/**/*.html`
All integrators that use these samples in the production code can be affected.
### Impact
A potential vulnerability has been discovered in one of CKEditor's 4 samples that are shipped with production code. The vulnerability allowed to execute JavaScript code by abusing the misconfigured [preview feature](https://ckeditor.com/cke4/addon/preview). It affects all users using the CKEditor 4 at version < 4.24.0-lts with affected samples used in a production environment.
### Patches
The p
GHSA
CKEditor4 Cross-site Scripting vulnerability in samples with enabled the preview feature
ghsa·2024-02-07
CVE-2024-24816 [MEDIUM] CWE-79 CKEditor4 Cross-site Scripting vulnerability in samples with enabled the preview feature
CKEditor4 Cross-site Scripting vulnerability in samples with enabled the preview feature
### Affected packages
The vulnerability has been discovered in the samples that use the [preview](https://ckeditor.com/cke4/addon/preview) feature:
* `samples/old/**/*.html`
* `plugins/[plugin name]/samples/**/*.html`
All integrators that use these samples in the production code can be affected.
### Impact
A potential vulnerability has been discovered in one of CKEditor's 4 samples that are shipped with production code. The vulnerability allowed to execute JavaScript code by abusing the misconfigured [preview feature](https://ckeditor.com/cke4/addon/preview). It affects all users using the CKEditor 4 at version < 4.24.0-lts with affected samples used in a production environment.
### Patches
The p
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://ckeditor.com/cke4/addon/previewhttps://github.com/ckeditor/ckeditor4/commit/8ed1a3c93d0ae5f49f4ecff5738ab8a2972194cbhttps://github.com/ckeditor/ckeditor4/security/advisories/GHSA-mw2c-vx6j-mg76https://ckeditor.com/cke4/addon/previewhttps://github.com/ckeditor/ckeditor4/commit/8ed1a3c93d0ae5f49f4ecff5738ab8a2972194cbhttps://github.com/ckeditor/ckeditor4/security/advisories/GHSA-mw2c-vx6j-mg76
2024-02-07
Published