CVE-2021-32809

Description

ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste functionality using malformed HTML, which could result in injecting arbitrary HTML into the editor. It affects all users using the CKEditor 4 plugins listed above at version >= 4.5.2. The problem has been recognized and patched. The fix will be available in version 4.16.2.

Risk Information

Base Score
5.4
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.206

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.2.5Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.2.0.2Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.2Windows
text editor which can be embedded into web pages (USN-5340-1) ckeditor_4.12.1+dfsg-1ubuntu0.1_all.debLinux
text editor which can be embedded into web pages (USN-5340-1) ckeditor_4.16.0+dfsg-2ubuntu0.1_all.debLinux
text editor which can be embedded into web pages (USN-5340-1) ckeditor_4.5.7+dfsg-2ubuntu0.18.04.1_all.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234