Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. drupal/drupal
  4. ›
  5. GHSA-qf65-hph9-453r

GHSA-qf65-hph9-453r: Drupal Cross-Site Scripting (XSS) affecting CKEditor Third-party library

May 15, 2024

The Drupal project uses the CKEditor, library for WYSIWYG editing. CKEditor has released a security update that impacts Drupal.

Vulnerabilities are possible if Drupal is configured to allow use of the CKEditor library for WYSIWYG editing. An attacker that can create or edit content (even without access to CKEditor themselves) may be able to exploit one or more Cross-Site Scripting (XSS) vulnerabilities to target users with access to the WYSIWYG CKEditor, including site admins with privileged access.

References

  • github.com/FriendsOfPHP/security-advisories/blob/master/drupal/drupal/2021-05-26.yaml
  • github.com/advisories/GHSA-qf65-hph9-453r
  • github.com/drupal/drupal
  • www.drupal.org/sa-core-2021-005

Code Behaviors & Features

Detect and mitigate GHSA-qf65-hph9-453r with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 8.0.0 before 8.9.16, all versions starting from 9.0.0 before 9.1.12, all versions starting from 9.2.0 before 9.2.4

Fixed versions

  • 8.9.16
  • 9.1.12
  • 9.2.4

Solution

Upgrade to versions 8.9.16, 9.1.12, 9.2.4 or above.

Impact 4.6 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Source file

packagist/drupal/drupal/GHSA-qf65-hph9-453r.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:13 +0000.