CVE-2021-32808

Description

ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malformed widget HTML, which could result in executing JavaScript code. It affects all users using the CKEditor 4 plugins listed above at version >= 4.13.0. The problem has been recognized and patched. The fix will be available in version 4.16.2.

Risk Information

Base Score
5.4
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
1.368

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.2.5Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.2.0.2Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.2Windows
text editor which can be embedded into web pages (USN-5340-1) ckeditor_4.12.1+dfsg-1ubuntu0.1_all.debLinux
text editor which can be embedded into web pages (USN-5340-1) ckeditor_4.16.0+dfsg-2ubuntu0.1_all.debLinux
text editor which can be embedded into web pages (USN-5340-1) ckeditor_4.5.7+dfsg-2ubuntu0.18.04.1_all.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234