3.5
CVSSv2

CVE-2022-24728

Published: 16/03/2022 Updated: 07/11/2023
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. This problem has been patched in version 4.18.0. There are currently no known workarounds.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ckeditor ckeditor

drupal drupal

oracle peoplesoft enterprise peopletools 8.58

oracle peoplesoft enterprise peopletools 8.59

oracle commerce merchandising 11.3.2

oracle financial services trade-based anti money laundering 8.0.7

oracle financial services trade-based anti money laundering 8.0.8

fedoraproject fedora 36

oracle financial services analytical applications infrastructure 8.1.2.0

oracle financial services analytical applications infrastructure 8.1.1.0

oracle application express

oracle financial services analytical applications infrastructure 8.1.2.1

oracle financial services behavior detection platform

oracle financial services analytical applications infrastructure

oracle financial services behavior detection platform 8.0.8.0

oracle financial services behavior detection platform 8.0.7.0

fedoraproject fedora 37

Vendor Advisories

Debian Bug report logs - #1015217 ckeditor3: CVE-2014-5191 CVE-2018-17960 CVE-2021-26271 CVE-2021-33829 CVE-2021-37695 CVE-2021-41165 CVE-2022-24728 CVE-2022-24729 Package: src:ckeditor3; Maintainer for src:ckeditor3 is Horde Maintainers <team+debian-horde-team@trackerdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inut ...