CKEditor是一套开源的、基于网页的文字编辑器。 CKEditor 4 [Clipboard]包中存在跨站脚本漏洞,该漏洞允许用户使用格式错误的 HTML 滥用粘贴功能,这可能导致将任意 HTML 注入编辑器。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-32808 | 7.6 HIGH | Cross-site scripting in ckeditor via abuse of undo functionality |
| CVE-2021-37695 | 7.3 HIGH | Execution of JavaScript code using malformed HTML in ckeditor |
No comments yet