VDB
CVE-2024-43411
CVE-2024-43411
PUBLISHED
CVSS 3.0999999046325684 LOW
CKEditor4 low-risk cross-site scripting (XSS) vulnerability linked to potential domain takeover
EPSS 0.42% · 35.5th percentile
Risk Scores
CVSS 3.1
3.0999999046325684
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N
EPSS Score
0.42%
35.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ckeditor | ckeditor4 | >= 4.22.0, < 4.25.0-lts, >= 4.22.0, < 4.25.0-lts |
| npm | ckeditor4 | 4.22.0, 4.22.0 |
Timeline
- Jan 21, 1970 Security Advisory
- Aug 21, 2024 CVE Published
- Aug 21, 2024 PoC Published
- Aug 22, 2024 EPSS Score
- Sep 12, 2024 EPSS Score
- Oct 2, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Oct 23, 2024 EPSS Score
- Nov 13, 2024 EPSS Score
- Nov 18, 2024 CVE Updated
- Dec 4, 2024 EPSS Score
- Dec 25, 2024 EPSS Score