5.4
CVE-2022-24728
- EPSS 0.72%
- Veröffentlicht 16.03.2022 16:15:10
- Zuletzt bearbeitet 21.11.2024 06:50:57
- Quelle security-advisories@github.com
- Teams Watchlist Login
- Unerledigt Login
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. This problem has been patched in version 4.18.0. There are currently no known workarounds.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oracle ≫ Application Express Version < 22.1.1
Oracle ≫ Commerce Merchandising Version11.3.2
Oracle ≫ Financial Services Analytical Applications Infrastructure Version >= 8.0.7.0.0 <= 8.1.0.0.0
Oracle ≫ Financial Services Analytical Applications Infrastructure Version8.1.1.0
Oracle ≫ Financial Services Analytical Applications Infrastructure Version8.1.2.0
Oracle ≫ Financial Services Analytical Applications Infrastructure Version8.1.2.1
Oracle ≫ Financial Services Behavior Detection Platform Version >= 8.1.1.0 <= 8.1.2.1
Oracle ≫ Financial Services Behavior Detection Platform Version8.0.7.0
Oracle ≫ Financial Services Behavior Detection Platform Version8.0.8.0
Oracle ≫ Financial Services Trade-based Anti Money Laundering Version8.0.7 SwEditionenterprise
Oracle ≫ Financial Services Trade-based Anti Money Laundering Version8.0.8 SwEditionenterprise
Oracle ≫ Peoplesoft Enterprise Peopletools Version8.58
Oracle ≫ Peoplesoft Enterprise Peopletools Version8.59
Fedoraproject ≫ Fedora Version36
Fedoraproject ≫ Fedora Version36
Fedoraproject ≫ Fedora Version37
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.72% | 0.716 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
nvd@nist.gov | 3.5 | 6.8 | 2.9 |
AV:N/AC:M/Au:S/C:N/I:P/A:N
|
security-advisories@github.com | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.