Duplicate Advisory: CKEditor Cross-site Scripting vulnerability
Moderate severity
GitHub Reviewed
Published
Nov 16, 2023
to the GitHub Advisory Database
•
Updated Feb 7, 2024
Withdrawn
This advisory was withdrawn on Feb 7, 2024
Description
Published by the National Vulnerability Database
Nov 16, 2023
Published to the GitHub Advisory Database
Nov 16, 2023
Reviewed
Nov 16, 2023
Withdrawn
Feb 7, 2024
Last updated
Feb 7, 2024
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-wh5w-82f3-wrxh. This link is maintained to preserve external references.
Original Description
A Cross-Site scripting vulnerability has been found in CKSource CKEditor affecting versions 4.15.1 and earlier. An attacker could send malicious javascript code through the /
ckeditor/samples/old/ajax.html
file and retrieve an authorized user's information.References