CVE-2020-9281: XSS
Published Mar 7, 2020
·Updated
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the ckeprotected syntax).
Other sources
CKEditor is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by the HTML Data Processor. A remote attacker could exploit this vulnerability using a specially crafted protected comment to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
— IBM
Affected Software
24 affected components
CKEditor CKEditor>=4.0<4.14
Fedoraproject Fedora=30
Fedoraproject Fedora=31
Fedoraproject Fedora=32
Drupal Drupal>=8.7.0<8.7.12
Drupal Drupal>=8.8.0<8.8.4
Oracle Agile PLM=9.3.5
Oracle Agile PLM=9.3.6
Oracle Application Express<20.2
Oracle JD Edwards EnterpriseOne Tools<9.2.5.2
Oracle PeopleSoft Enterprise PeopleTools
Oracle PeopleSoft Enterprise PeopleTools=8.56
Oracle PeopleSoft Enterprise PeopleTools=8.57
Oracle PeopleSoft Enterprise PeopleTools=8.58
Oracle Siebel Apps - Customer Order Management<21.0
Oracle WebCenter Portal=11.1.1.9.0
Oracle WebCenter Portal=12.2.1.3.0
Oracle WebCenter Portal=12.2.1.4.0
Oracle Banking Enterprise Default Management=2.6.2
Oracle Banking Enterprise Default Management=2.7.0
Oracle Banking Enterprise Default Management=2.7.1
Oracle Banking Enterprise Default Management=2.10.0
Oracle Banking Enterprise Default Management=2.12.0
Oracle Banking Enterprise Default Managment>=2.3.0<=2.4.0
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Mar 7, 2020
CVE Published
via MITRE·12:02 AM
Data Sourced
via MITRE·12:02 AM
Description
Data Sourced
via NVD·01:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Aug 3, 2024
Data Sourced
via IBM·05:47 PM
DescriptionSeverityAffected Software