漏洞标题
代码片段 GeSHi插件存在跨站脚本(XSS)漏洞
漏洞描述信息
N/A
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
漏洞类别
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
漏洞标题
Code Snippet GeSHi plugin has reflected cross-site scripting (XSS) vulnerability
漏洞描述信息
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A potential vulnerability has been discovered in CKEditor 4 Code Snippet GeSHi plugin. The vulnerability allowed a reflected XSS attack by exploiting a flaw in the GeSHi syntax highlighter library hosted by the victim. The GeSHi library was included as a vendor dependency in CKEditor 4 source files. In a specific scenario, an attacker could craft a malicious script that could be executed by sending a request to the GeSHi library hosted on a PHP web server. The GeSHi library is no longer actively maintained. Due to the lack of ongoing support and updates, potential security vulnerabilities have been identified with its continued use. To mitigate these risks and enhance the overall security of the CKEditor 4, we have decided to completely remove the GeSHi library as a dependency. This change aims to maintain a secure environment and reduce the risk of any security incidents related to outdated or unsupported software. The fix is be available in version 4.25.0-lts.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
漏洞类别
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
漏洞标题
CKEditor4 安全漏洞
漏洞描述信息
CKEditor4是CKEditor开源的一个企业级 WYSIWYG 编辑器。 CKEditor4 4.25.0-lts之前版本存在安全漏洞。攻击者利用该漏洞可以编写恶意脚本,该脚本可以通过向托管在 PHP Web 服务器上的 GeSHi 库发送请求来执行。
CVSS信息
N/A
漏洞类别
其他