Description
The Open Link is a CKEditor plugin, extending context menu with a possibility to open link in a new tab. The vulnerability allowed to execute JavaScript code by abusing link href attribute. It affects all users using the Open Link plugin at version < **1.0.5**.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 08 Aug 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mlewand
Mlewand open Link |
|
| CPEs | cpe:2.3:a:mlewand:open_link:*:*:*:*:*:ckeditor:*:* | |
| Vendors & Products |
Mlewand
Mlewand open Link |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T03:57:40.013Z
Reserved: 2024-06-10T19:54:41.360Z
Link: CVE-2024-37888
Updated: 2024-07-11T19:17:21.693Z
Status : Modified
Published: 2024-06-14T18:15:27.790
Modified: 2024-11-21T09:24:28.543
Link: CVE-2024-37888
No data.
OpenCVE Enrichment
No data.
Weaknesses