Back to search
CVE-2021-33829
Published: Jun 9, 2021
Modified: Aug 3, 2024
PUBLISHED
Description
A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!> is mishandled.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://www.drupal.org/sa-core-2021-003
x_refsource_CONFIRM
FEDORA-2021-51457da891
vendor-advisory
x_refsource_FEDORA
FEDORA-2021-72176a63a8
vendor-advisory
x_refsource_FEDORA
FEDORA-2021-87578dca12
vendor-advisory
x_refsource_FEDORA
[debian-lts-announce] 20211109 [SECURITY] [DLA 2813-1] ckeditor security update
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now