CVE-2020-9281

Description

A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted protected comment (with the cke_protected syntax).

Risk Information

Base Score
6.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
1.194

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.2.0Windows
Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.56Windows
Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.57Windows
Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.58Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.0.3.5Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.1.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.1Windows
text editor which can be embedded into web pages (USN-5340-1) ckeditor_4.12.1+dfsg-1ubuntu0.1_all.debLinux
text editor which can be embedded into web pages (USN-5340-1) ckeditor_4.16.0+dfsg-2ubuntu0.1_all.debLinux
text editor which can be embedded into web pages (USN-5340-1) ckeditor_4.5.7+dfsg-2ubuntu0.18.04.1_all.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234