CVE-2018-17960: XSS
CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste.
Other sources
CKEditor is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a source-mode paste to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-17960?
CVE-2018-17960 is a vulnerability in CKEditor 4.x that allows user-assisted cross-site scripting (XSS) attacks.
How does CVE-2018-17960 work?
CVE-2018-17960 allows an attacker to execute XSS inside the CKEditor source area by persuading the victim to switch to source mode and paste a specially crafted HTML code.
Which software versions are affected by CVE-2018-17960?
CVE-2018-17960 affects TYPO3 CMS versions 8.0.0 to 8.7.21 and 9.0.0 to 9.5.2, as well as CKEditor versions up to 4.11.0.
What is the severity of CVE-2018-17960?
CVE-2018-17960 has a severity rating of 6.1 (medium).
How can I fix CVE-2018-17960?
To fix CVE-2018-17960, you should update CKEditor to version 4.11.0 or later.