Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-41164


CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0. The problem has been recognized and patched. The fix will be available in version 4.17.0.


Published

2021-11-17T19:15:08.913

Last Modified

2024-11-21T06:25:38.570

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.2 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:S/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: SINGLE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

6.8

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-79
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ckeditor ckeditor < 4.17.0 Yes
Application drupal drupal < 8.9.20 Yes
Application drupal drupal < 9.1.14 Yes
Application drupal drupal < 9.2.9 Yes
Application oracle banking_apis ≤ 18.3 Yes
Application oracle banking_apis 19.1 Yes
Application oracle banking_apis 19.2 Yes
Application oracle banking_apis 20.1 Yes
Application oracle banking_apis 21.1 Yes
Application oracle banking_digital_experience ≤ 18.3 Yes
Application oracle banking_digital_experience 19.1 Yes
Application oracle banking_digital_experience 19.2 Yes
Application oracle banking_digital_experience 20.1 Yes
Application oracle banking_digital_experience 21.1 Yes
Application oracle agile_plm 9.3.6 Yes
Application oracle application_express < 22.1 Yes
Application oracle commerce_guided_search 11.3.2 Yes
Application oracle peoplesoft_enterprise_peopletools 8.58 Yes
Application oracle peoplesoft_enterprise_peopletools 8.59 Yes
Application oracle webcenter_portal 12.2.1.3.0 Yes
Application oracle webcenter_portal 12.2.1.4.0 Yes
Operating System fedoraproject fedora 36 Yes
Operating System fedoraproject fedora 37 Yes

References