312
VMScore

CVE-2021-32809

Published: 12/08/2021 Updated: 07/11/2023
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste functionality using malformed HTML, which could result in injecting arbitrary HTML into the editor. It affects all users using the CKEditor 4 plugins listed above at version >= 4.5.2. The problem has been recognized and patched. The fix will be available in version 4.16.2.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ckeditor ckeditor

fedoraproject fedora 33

fedoraproject fedora 34

fedoraproject fedora 35

oracle peoplesoft enterprise peopletools 8.57

oracle peoplesoft enterprise peopletools 8.58

oracle commerce guided search 11.3.2

oracle peoplesoft enterprise peopletools 8.59

oracle commerce merchandising 11.3.2

oracle jd edwards enterpriseone tools

oracle documaker 12.6.3

oracle documaker 12.6.4

oracle banking party management 2.7.0

oracle financial services analytical applications infrastructure

oracle application express

Vendor Advisories

Debian Bug report logs - #992291 ckeditor: CVE-2021-32809 Package: src:ckeditor; Maintainer for src:ckeditor is Debian Javascript Maintainers <pkg-javascript-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 16 Aug 2021 20:00:02 UTC Severity: important Tags: security, up ...
Several security issues were fixed in CKEditor ...