CVE-2023-4771 PUBLISHED CVSS 6.099999904632568 MEDIUM

A Cross-Site scripting vulnerability has been found in CKSource CKEditor affecting versions 4.15.1 and earlier. An attacker could send malicious javascript code through the /ckeditor/samples/old/ajax.html file and retrieve an authorized user's information.

EPSS 22.31% · 95.8th percentile

Risk Scores

CVSS v3.1
6.099999904632568
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
22.31%
95.8th percentile

Affected Products

VendorProductVersions
cksourceckeditor0
npmckeditor40
CKSourceCKEditor0

Timeline

References

Open in Interactive Console →