CVE-2021-37695 HIGH

CVE-2021-37695: Execution of JavaScript code using malformed HTML in ckeditor

Vendor Ckeditor
Product ckeditor4
Weakness CWE-79 · XSS
Published August 12, 2021
Last update August 4, 2024

CVSS base score

7.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

What the vulnerability does

01Description

ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed to inject malformed Fake Objects HTML, which could result in executing JavaScript code. It affects all users using the CKEditor 4 plugins listed above at version < 4.16.2. The problem has been recognized and patched. The fix will be available in version 4.16.2.

Key dates

02Disclosure timeline

August 12, 2021 CVE published
August 4, 2024 Record updated

Related vulnerabilities

04Related CVE