5.4
CVE-2022-24728
- EPSS 1.21%
- Veröffentlicht 16.03.2022 16:15:10
- Zuletzt bearbeitet 21.11.2024 06:50:57
- Erkennungen
Cross-site Scripting in CKEditor4
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. This problem has been patched in version 4.18.0. There are currently no known workarounds.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oracle ≫ Application Express Version < 22.1.1
Oracle ≫ Commerce Merchandising Version 11.3.2
Oracle ≫ Financial Services Analytical Applications Infrastructure Version >= 8.0.7.0.0 <= 8.1.0.0.0
Oracle ≫ Financial Services Analytical Applications Infrastructure Version 8.1.1.0
Oracle ≫ Financial Services Analytical Applications Infrastructure Version 8.1.2.0
Oracle ≫ Financial Services Analytical Applications Infrastructure Version 8.1.2.1
Oracle ≫ Financial Services Behavior Detection Platform Version >= 8.1.1.0 <= 8.1.2.1
Oracle ≫ Financial Services Behavior Detection Platform Version 8.0.7.0
Oracle ≫ Financial Services Behavior Detection Platform Version 8.0.8.0
Oracle ≫ Financial Services Trade-based Anti Money Laundering Version 8.0.7 SwEdition enterprise
Oracle ≫ Financial Services Trade-based Anti Money Laundering Version 8.0.8 SwEdition enterprise
Oracle ≫ Peoplesoft Enterprise Peopletools Version 8.58
Oracle ≫ Peoplesoft Enterprise Peopletools Version 8.59
Fedoraproject ≫ Fedora Version 36
Fedoraproject ≫ Fedora Version 36
Fedoraproject ≫ Fedora Version 37
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.21% | 0.654 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
| NIST | 3.5 | 6.8 | 2.9 |
AV:N/AC:M/Au:S/C:N/I:P/A:N
|
| security-advisories@github.com | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
https://www.oracle.com/security-alerts/cpujul2022.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VR76VBN5GW5QUBJFHVXRX36UZ6YTCMW6/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WOZGMCYDB2OKKULFXZKM6V7JJW4ZZHJP/
https://ckeditor.com/cke4/release/CKEditor-4.18.0
https://github.com/ckeditor/ckeditor4/commit/d158413449692d920a778503502dcb22881bc949
https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-4fc4-4p5g-6w89
https://www.drupal.org/sa-core-2022-005