Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-24728


CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. This problem has been patched in version 4.18.0. There are currently no known workarounds.


Published

2022-03-16T16:15:10.907

Last Modified

2024-11-21T06:50:57.820

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:S/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: SINGLE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

6.8

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-79
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ckeditor ckeditor < 4.18.0 Yes
Application drupal drupal < 9.2.15 Yes
Application drupal drupal < 9.3.8 Yes
Application oracle application_express < 22.1.1 Yes
Application oracle commerce_merchandising 11.3.2 Yes
Application oracle financial_services_analytical_applications_infrastructure ≤ 8.1.0.0.0 Yes
Application oracle financial_services_analytical_applications_infrastructure 8.1.1.0 Yes
Application oracle financial_services_analytical_applications_infrastructure 8.1.2.0 Yes
Application oracle financial_services_analytical_applications_infrastructure 8.1.2.1 Yes
Application oracle financial_services_behavior_detection_platform ≤ 8.1.2.1 Yes
Application oracle financial_services_behavior_detection_platform 8.0.7.0 Yes
Application oracle financial_services_behavior_detection_platform 8.0.8.0 Yes
Application oracle financial_services_trade-based_anti_money_laundering 8.0.7 Yes
Application oracle financial_services_trade-based_anti_money_laundering 8.0.8 Yes
Application oracle peoplesoft_enterprise_peopletools 8.58 Yes
Application oracle peoplesoft_enterprise_peopletools 8.59 Yes
Operating System fedoraproject fedora 36 Yes
Operating System fedoraproject fedora 36 Yes
Operating System fedoraproject fedora 37 Yes

References