CVE-2020-9281 PUBLISHED

A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).

EPSS 1.19% · 78.7th percentile

Risk Scores

EPSS Score
1.19%
78.7th percentile

Affected Products

VendorProductVersions
Bitnamidrupal8.7.0, 8.8.0
Bitnamidrupal8.7.0, 8.8.0, 8.7.0

Timeline

References

Open in Interactive Console →