CKEditor 4.x prima 4.11.0 permette all’utente assistita XSS che coinvolge una pasta fonte-mode. |
http://www.securityfocus.com/bid/109205 https://ckeditor.com/blog/CKEditor-4.11-with-emoji-dropdown-and-auto-link-on-typing-released/ https://ckeditor.com/cke4/release/CKEditor-4.11.0 https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-17960 |
Vulnerabilità: CVE-2018-17960
