5.4
CVSSv3

CVE-2021-37695

Published: 13/08/2021 Updated: 07/11/2023
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed to inject malformed Fake Objects HTML, which could result in executing JavaScript code. It affects all users using the CKEditor 4 plugins listed above at version < 4.16.2. The problem has been recognized and patched. The fix will be available in version 4.16.2.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ckeditor ckeditor

debian debian linux 9.0

fedoraproject fedora 33

fedoraproject fedora 34

fedoraproject fedora 35

oracle peoplesoft enterprise peopletools 8.57

oracle financial services analytical applications infrastructure 8.0.3

oracle peoplesoft enterprise peopletools 8.58

oracle commerce guided search 11.3.2

oracle peoplesoft enterprise peopletools 8.59

oracle commerce merchandising 11.3.2

oracle jd edwards enterpriseone tools

oracle documaker 12.6.3

oracle documaker 12.6.4

oracle financial services model management and governance

oracle banking party management 2.7.0

oracle financial services analytical applications infrastructure

oracle application express

Vendor Advisories

Several security issues were fixed in CKEditor ...
Debian Bug report logs - #992290 ckeditor: CVE-2021-37695 Package: src:ckeditor; Maintainer for src:ckeditor is Debian Javascript Maintainers &lt;pkg-javascript-devel@listsaliothdebianorg&gt;; Reported by: Salvatore Bonaccorso &lt;carnil@debianorg&gt; Date: Mon, 16 Aug 2021 19:57:04 UTC Severity: important Tags: security, up ...
Debian Bug report logs - #1015217 ckeditor3: CVE-2014-5191 CVE-2018-17960 CVE-2021-26271 CVE-2021-33829 CVE-2021-37695 CVE-2021-41165 CVE-2022-24728 CVE-2022-24729 Package: src:ckeditor3; Maintainer for src:ckeditor3 is Horde Maintainers &lt;team+debian-horde-team@trackerdebianorg&gt;; Reported by: Moritz Mühlenhoff &lt;jmm@inut ...