CVE-2021-41164

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in npm/ckeditor4

Identifiers

CVE-2021-41164, GHSA-pvmx-g8h5-cprj

Package Slug

npm/ckeditor4

Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Description

CKEditor4 is an open source WYSIWYG HTML editor. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code.

Affected Versions

All versions starting from 4.0 before 4.17.0

Solution

Upgrade to version 4.17.0 or above.

Last Modified

2021-11-22

source