CVE-2024-13245: CKEditor 4 LTS - WYSIWYG HTML editor - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024-009
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CKEditor 4 LTS - WYSIWYG HTML editor allows Cross-Site Scripting (XSS).This issue affects CKEditor 4 LTS - WYSIWYG HTML editor: from 1.0.0 before 1.0.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13245?
CVE-2024-13245 is classified as a Critical severity vulnerability due to its potential for Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2024-13245?
To fix CVE-2024-13245, upgrade Drupal CKEditor 4 LTS from version 1.0.0 to 1.0.1 or later.
What systems are affected by CVE-2024-13245?
CVE-2024-13245 affects Drupal CKEditor 4 LTS versions from 1.0.0 to earlier than 1.0.1.
What are the risks associated with CVE-2024-13245?
The risks of CVE-2024-13245 include unauthorized access to user data and potential site compromise through XSS attacks.
Is there a workaround for CVE-2024-13245?
There is no recommended workaround for CVE-2024-13245 other than applying the necessary update to the software.