Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor (in versions 4.5.10 through 4.9.1; fixed in 4.9.2), as used in Drupal 8 before 8.4.7 and 8.5.x before 8.5.2 and other products, allows remote attackers to inject arbitrary web script through a crafted IMG element.
2018-04-19T17:29:00.257
2024-11-21T04:15:49.717
Modified
CVSSv3.0: 6.1 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ckeditor | enhanced_image | < 4.9.2 | Yes |
Application | drupal | drupal | < 8.4.7 | Yes |
Application | drupal | drupal | < 8.5.2 | Yes |