CVE-2020-27193: XSS
A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.
Other sources
CKSource CKEditor is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by the Color Button dialog. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
— IBM
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-27193.
What is the severity of CVE-2020-27193?
CVE-2020-27193 has a severity of 6.1, which is considered medium.
Which software versions are affected by CVE-2020-27193?
The Color Dialog plugin for CKEditor version 4.15.0 is affected by CVE-2020-27193.
How can remote attackers exploit CVE-2020-27193?
Remote attackers can exploit CVE-2020-27193 by persuading a user to copy and paste crafted HTML code into one of the editor inputs.
Is there a patch available for CVE-2020-27193?
Yes, a security patch has been released for CVE-2020-27193. It is recommended to update to CKEditor version 4.15.1.