← Back
CVE-2021-41164
high
CVSS 8.2
CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The...
Summary
CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result i...
AI summary openai / gpt-4o
CKEditor4のAdvanced Content Filter(ACF)モジュールに脆弱性が発見されました。この問題は、バージョン4.17.0未満の利用者に影響を及ぼし、コンテンツの不正なHTMLを注入してJavaScriptコードを実行させる可能性があります。この脆弱性は既に認識され、バージョン4.17.0で修正されています。
❓ What is the problem
CKEditor4のACFモジュールにおける不正なHTML注入の脆弱性。
📍 Affected scope
CKEditor4のバージョン4.17.0未満のすべてのユーザー。
🔥 Severity
この脆弱性により、不正なHTMLを通じてJavaScriptコードが実行される可能性があるため、非常に重要です。
🔧 How to fix
バージョン4.17.0にアップデートしてください。
🛡️ Workaround
情報なし
🔍 Detection
CKEditor4のバージョン番号を確認して、4.17.0未満である場合は影響を受けている可能性があります。
References
- advisory af854a3a-2127-422b-91ae-364da2661108
- advisory af854a3a-2127-422b-91ae-364da2661108
- patch af854a3a-2127-422b-91ae-364da2661108
- patch af854a3a-2127-422b-91ae-364da2661108
- patch af854a3a-2127-422b-91ae-364da2661108
- web af854a3a-2127-422b-91ae-364da2661108
- web af854a3a-2127-422b-91ae-364da2661108
- web af854a3a-2127-422b-91ae-364da2661108