ckeditor-wordcount-plugin vulnerable to Cross-site Scripting in Source Mode of Editor
Moderate severity
GitHub Reviewed
Published
Jul 10, 2023
in
w8tcha/CKEditor-WordCount-Plugin
•
Updated Nov 9, 2023
Description
Published to the GitHub Advisory Database
Jul 10, 2023
Reviewed
Jul 10, 2023
Published by the National Vulnerability Database
Jul 21, 2023
Last updated
Nov 9, 2023
Problem
It has been discovered that the
ckeditor-wordcount-plugin
plugin for CKEditor4 is susceptible to cross-site scripting when switching to the source code mode.Solution
Update to version 1.17.12 of the
ckeditor-wordcount-plugin
plugin.Credits
References