CKeditor: XSS vulnerabilities in the core module
Issue date: 29-06-2022Affects versions: 15.0, 14.7, 13.4
Security Issue ID
SECURITY-297
SECURITY-306
Affected Product Version(s)
13.4.17, 15.0.1, 14.7.7 and all previous versions
Severity
medium/high
Description
The vulnerability allowed to inject malformed comments HTML bypassing content sanitization, which could result in executing JavaScript code. See security advisory for more details.
Instructions
Update to the latest version.