← 戻る
CVE-2021-41164
high
CVSS 8.2
CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The...
概要
CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result i...
AI要約 openai / gpt-4o
CKEditor4のAdvanced Content Filter(ACF)モジュールに脆弱性が発見されました。この問題は、バージョン4.17.0未満の利用者に影響を及ぼし、コンテンツの不正なHTMLを注入してJavaScriptコードを実行させる可能性があります。この脆弱性は既に認識され、バージョン4.17.0で修正されています。
❓ 何が問題か
CKEditor4のACFモジュールにおける不正なHTML注入の脆弱性。
📍 影響範囲
CKEditor4のバージョン4.17.0未満のすべてのユーザー。
🔥 重要度
この脆弱性により、不正なHTMLを通じてJavaScriptコードが実行される可能性があるため、非常に重要です。
🔧 修正方法
バージョン4.17.0にアップデートしてください。
🛡️ 暫定回避
情報なし
🔍 検知方法
CKEditor4のバージョン番号を確認して、4.17.0未満である場合は影響を受けている可能性があります。
参照URL
- advisory af854a3a-2127-422b-91ae-364da2661108
- advisory af854a3a-2127-422b-91ae-364da2661108
- patch af854a3a-2127-422b-91ae-364da2661108
- patch af854a3a-2127-422b-91ae-364da2661108
- patch af854a3a-2127-422b-91ae-364da2661108
- web af854a3a-2127-422b-91ae-364da2661108
- web af854a3a-2127-422b-91ae-364da2661108
- web af854a3a-2127-422b-91ae-364da2661108