CVE-2021-33829

Description

A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!> is mishandled.

Risk Information

Base Score
6.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
49.674

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.2Windows
text editor which can be embedded into web pages (USN-5340-1) ckeditor_4.12.1+dfsg-1ubuntu0.1_all.debLinux
text editor which can be embedded into web pages (USN-5340-1) ckeditor_4.16.0+dfsg-2ubuntu0.1_all.debLinux
text editor which can be embedded into web pages (USN-5340-1) ckeditor_4.5.7+dfsg-2ubuntu0.18.04.1_all.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234