CVE-2021-33829: XSS
A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!> is mishandled.
Other sources
A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!> is mishandled.
CKEditor is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
Drupal core - Critical - Cross-site scripting - SA-CORE-2021-003
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-33829?
CVE-2021-33829 is a vulnerability in Drupal core that allows for cross-site scripting (XSS) attacks.
How severe is CVE-2021-33829?
CVE-2021-33829 has a severity rating of 7.2, which is considered high.
How does CVE-2021-33829 affect Drupal websites?
CVE-2021-33829 can allow remote attackers to inject malicious scripts into a Drupal website, which can be executed by visitors to the site, compromising their browsing security.
What versions of Drupal are affected by CVE-2021-33829?
Versions 7.x, 8.x, and 9.x of Drupal are affected by CVE-2021-33829.
Where can I find more information about CVE-2021-33829 and its remediation?
For more information about CVE-2021-33829 and its remediation, you can visit the Drupal Security Advisory SA-CORE-2021-003 or the IBM X-Force Exchange website.