CVE-2021-33829

MEDIUM6.1EPSS 65.5%

ckeditor4 vulnerable to cross-site scripting

發布日:2021/6/21修改日:2025/12/10
也稱為:GHSA-rgx6-rjj4-c388BIT-drupal-2021-33829DRUPAL-CORE-2021-003

描述

A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because `--!>` is mishandled.

受影響套件(8)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

參考連結(15)