CVE-2021-41165 HIGH

CVE-2021-41165: HTML comments vulnerability allowing to execute JavaScript code

Vendor Ckeditor
Product ckeditor4
Weakness CWE-79 · XSS
Published November 17, 2021
Last update August 4, 2024

CVSS base score

8.2/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality High
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L

What the vulnerability does

Description

CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed comments HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0. The problem has been recognized and patched. The fix will be available in version 4.17.0.

Key dates

Disclosure timeline

November 17, 2021 CVE published
August 4, 2024 Record updated