CKEditor: HTML processing module CVE-2022-24728
Issue date: 29-06-2022Affects versions: 15.0, 14.7, 13.4
Security Issue ID
SECURITY-315
Affected Product Version(s)
13.4.17, 15.0.1, 14.7.7 and all previous versions
Severity
medium/high
Description
A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. This problem has been patched in version 4.18.0. There are currently no known workarounds.
Instructions
Update to the latest version.