ckeditor@4.8.0 vulnerabilities

JavaScript WYSIWYG web text editor.

Direct Vulnerabilities

Known vulnerabilities in the ckeditor package. This does not include vulnerabilities belonging to this package’s dependencies.

Vulnerability Vulnerable Version
Cross-site Scripting (XSS)

ckeditor is a A highly configurable WYSIWYG HTML editor.

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) attacks. It was possible to execute XSS inside CKEditor after persuading the victim to switch CKEditor to source mode, then paste a specially crafted HTML code, prepared by the attacker, into the opened CKEditor source area, and switch back to WYSIWYG mode.

How to fix Cross-site Scripting (XSS)?

Upgrade ckeditor to version 4.11.0 or higher.

>=4.0.0 <4.11.0