CVE-2024-43411
published 2024-08-21CVE-2024-43411: CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A theoretical vulnerability has been identified in CKEditor 4.22 (and above). In a highly…
PriorityP410low3.1CVSS 3.1
AVNACHPRHUIRSUCLILAN
EPSS
0.40%
32.3th percentile
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A theoretical vulnerability has been identified in CKEditor 4.22 (and above). In a highly unlikely scenario where an attacker gains control over the https://cke4.ckeditor.com domain, they could potentially execute an attack on CKEditor 4 instances. The issue impacts only editor instances with enabled version notifications. Please note that this feature is disabled by default in all CKEditor 4 LTS versions. Therefore, if you use CKEditor 4 LTS, it is highly unlikely that you are affected by this vulnerability. If you are unsure, please contact us. The fix is available in version 4.25.0-lts.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ckeditor | ckeditor | >= 0 < 4.5.7+dfsg-2ubuntu0.16.04.1~esm2 | 4.5.7+dfsg-2ubuntu0.16.04.1~esm2 |
| ckeditor | ckeditor | >= 0 < 4.5.7+dfsg-2ubuntu0.18.04.1+esm1 | 4.5.7+dfsg-2ubuntu0.18.04.1+esm1 |
| ckeditor | ckeditor | >= 0 < 4.12.1+dfsg-1ubuntu0.1+esm1 | 4.12.1+dfsg-1ubuntu0.1+esm1 |
| ckeditor | ckeditor | >= 0 < 4.16.2+dfsg-1ubuntu0.1~esm1 | 4.16.2+dfsg-1ubuntu0.1~esm1 |
| ckeditor | ckeditor | >= 0 < 4.22.1+dfsg1-2ubuntu0.24.04.1~esm1 | 4.22.1+dfsg1-2ubuntu0.24.04.1~esm1 |
| ckeditor | ckeditor4 | — | — |
| ckeditor | ckeditor4 | >= 4.22.0 < 4.25.0 | 4.25.0 |
| debian | ckeditor | — | — |
CVSS provenance
nvdv3.13.1LOWCVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N
osv5.4MEDIUM
vendor_ubuntu5.4MEDIUM
vendor_debian3.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
ckeditor vulnerabilities
osv·2025-02-06·CVSS 5.4
CVE-2022-24728 [MEDIUM] ckeditor vulnerabilities
ckeditor vulnerabilities
Kevin Backhouse discovered that CKEditor did not properly sanitize HTML
content. An attacker could possibly use this issue to perform cross site
scripting and obtain sensitive information. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2022-24728)
It was discovered that CKEditor did not properly handle the creation of
editor instances in the Iframe Dialog and Media Embed packages. An
attacker could possibly use this issue to perform cross site scripting
and obtain sensitive information. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2023-28439)
It was discovered that CKEditor did not properly handle parsing HTML
content. An attacker could possibly
GHSA
CKEditor4 low-risk cross-site scripting (XSS) vulnerability linked to potential domain takeover
ghsa·2024-08-21
CVE-2024-43411 [MEDIUM] CWE-79 CKEditor4 low-risk cross-site scripting (XSS) vulnerability linked to potential domain takeover
CKEditor4 low-risk cross-site scripting (XSS) vulnerability linked to potential domain takeover
### Affected Packages
The issue impacts only editor instances with enabled [version notifications](https://ckeditor.com/docs/ckeditor4/latest/api/CKEDITOR_config.html#cfg-versionCheck).
Please note that this feature is disabled by default in all CKEditor 4 LTS versions. Therefore, if you use CKEditor 4 LTS, it is highly unlikely that you are affected by this vulnerability. If you are unsure, please [contact us](mailto:[email protected]).
### Impact
A theoretical vulnerability has been identified in CKEditor 4.22 (and above). In a highly unlikely scenario where an attacker gains control over the https://cke4.ckeditor.com domain, they could potentially execute an attack on CKEditor 4 inst
OSV
CVE-2024-43411: CKEditor4 is an open source what-you-see-is-what-you-get HTML editor
osv·2024-08-21·CVSS 3.1
CVE-2024-43411 [LOW] CVE-2024-43411: CKEditor4 is an open source what-you-see-is-what-you-get HTML editor
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A theoretical vulnerability has been identified in CKEditor 4.22 (and above). In a highly unlikely scenario where an attacker gains control over the https://cke4.ckeditor.com domain, they could potentially execute an attack on CKEditor 4 instances. The issue impacts only editor instances with enabled version notifications. Please note that this feature is disabled by default in all CKEditor 4 LTS versions. Therefore, if you use CKEditor 4 LTS, it is highly unlikely that you are affected by this vulnerability. If you are unsure, please contact us. The fix is available in version 4.25.0-lts.
OSV
CKEditor4 low-risk cross-site scripting (XSS) vulnerability linked to potential domain takeover
osv·2024-08-21
CVE-2024-43411 [MEDIUM] CKEditor4 low-risk cross-site scripting (XSS) vulnerability linked to potential domain takeover
CKEditor4 low-risk cross-site scripting (XSS) vulnerability linked to potential domain takeover
### Affected Packages
The issue impacts only editor instances with enabled [version notifications](https://ckeditor.com/docs/ckeditor4/latest/api/CKEDITOR_config.html#cfg-versionCheck).
Please note that this feature is disabled by default in all CKEditor 4 LTS versions. Therefore, if you use CKEditor 4 LTS, it is highly unlikely that you are affected by this vulnerability. If you are unsure, please [contact us](mailto:[email protected]).
### Impact
A theoretical vulnerability has been identified in CKEditor 4.22 (and above). In a highly unlikely scenario where an attacker gains control over the https://cke4.ckeditor.com domain, they could potentially execute an attack on CKEditor 4 inst
Ubuntu
CKEditor vulnerabilities
vendor_ubuntu·2025-02-06·CVSS 5.4
CVE-2024-24816 [MEDIUM] CKEditor vulnerabilities
Title: CKEditor vulnerabilities
Summary: Several security issues were fixed in CKEditor.
Kevin Backhouse discovered that CKEditor did not properly sanitize HTML
content. An attacker could possibly use this issue to perform cross site
scripting and obtain sensitive information. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2022-24728)
It was discovered that CKEditor did not properly handle the creation of
editor instances in the Iframe Dialog and Media Embed packages. An
attacker could possibly use this issue to perform cross site scripting
and obtain sensitive information. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2023-28439)
It was discovered that CKEditor did not
Debian
CVE-2024-43411: ckeditor - CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A theoreti...
vendor_debian·2024·CVSS 3.1
CVE-2024-43411 [LOW] CVE-2024-43411: ckeditor - CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A theoreti...
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A theoretical vulnerability has been identified in CKEditor 4.22 (and above). In a highly unlikely scenario where an attacker gains control over the https://cke4.ckeditor.com domain, they could potentially execute an attack on CKEditor 4 instances. The issue impacts only editor instances with enabled version notifications. Please note that this feature is disabled by default in all CKEditor 4 LTS versions. Therefore, if you use CKEditor 4 LTS, it is highly unlikely that you are affected by this vulnerability. If you are unsure, please contact us. The fix is available in version 4.25.0-lts.
Scope: local
bookworm: resolved
bullseye: resolved
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-08-21
Published