cbcvebase.
CVE-2024-43411
published 2024-08-21

CVE-2024-43411: CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A theoretical vulnerability has been identified in CKEditor 4.22 (and above). In a highly…

PriorityP410low3.1CVSS 3.1
AVNACHPRHUIRSUCLILAN
EPSS
0.40%
32.3th percentile
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A theoretical vulnerability has been identified in CKEditor 4.22 (and above). In a highly unlikely scenario where an attacker gains control over the https://cke4.ckeditor.com domain, they could potentially execute an attack on CKEditor 4 instances. The issue impacts only editor instances with enabled version notifications. Please note that this feature is disabled by default in all CKEditor 4 LTS versions. Therefore, if you use CKEditor 4 LTS, it is highly unlikely that you are affected by this vulnerability. If you are unsure, please contact us. The fix is available in version 4.25.0-lts.

Affected

8 ranges
VendorProductVersion rangeFixed in
ckeditorckeditor>= 0 < 4.5.7+dfsg-2ubuntu0.16.04.1~esm24.5.7+dfsg-2ubuntu0.16.04.1~esm2
ckeditorckeditor>= 0 < 4.5.7+dfsg-2ubuntu0.18.04.1+esm14.5.7+dfsg-2ubuntu0.18.04.1+esm1
ckeditorckeditor>= 0 < 4.12.1+dfsg-1ubuntu0.1+esm14.12.1+dfsg-1ubuntu0.1+esm1
ckeditorckeditor>= 0 < 4.16.2+dfsg-1ubuntu0.1~esm14.16.2+dfsg-1ubuntu0.1~esm1
ckeditorckeditor>= 0 < 4.22.1+dfsg1-2ubuntu0.24.04.1~esm14.22.1+dfsg1-2ubuntu0.24.04.1~esm1
ckeditorckeditor4
ckeditorckeditor4>= 4.22.0 < 4.25.04.25.0
debianckeditor

CVSS provenance

nvdv3.13.1LOWCVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N
osv5.4MEDIUM
vendor_ubuntu5.4MEDIUM
vendor_debian3.1LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.