Cross-site Scripting (XSS) Affecting org.webjars.npm:ckeditor4 package, versions [,4.19.0)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team

    Threat Intelligence

    EPSS
    0.16% (54th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-JAVA-ORGWEBJARSNPM-2430345
  • published 20 Mar 2022
  • disclosed 16 Mar 2022
  • credit Kevin Backhouse

How to fix?

Upgrade org.webjars.npm:ckeditor4 to version 4.19.0 or higher.

Overview

org.webjars.npm:ckeditor4 is a JavaScript WYSIWYG web text editor.

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via malformed HTML injection to the core HTML processing module, which may allow execution of JavaScript code.

CVSS Scores

version 3.1
Expand this section

Snyk

Recommended
5.4 medium
  • Attack Vector (AV)
    Network
  • Attack Complexity (AC)
    Low
  • Privileges Required (PR)
    Low
  • User Interaction (UI)
    Required
  • Scope (S)
    Changed
  • Confidentiality (C)
    Low
  • Integrity (I)
    Low
  • Availability (A)
    None
Expand this section

NVD

5.4 medium