Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2518 | CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A theoretical vulnerability has been identified in CKEditor 4.22 (and above). In a highly unlikely scenario where an attacker gains control over the https://cke4.ckeditor.com domain, they could potentially execute an attack on CKEditor 4 instances. The issue impacts only editor instances with enabled version notifications. Please note that this feature is disabled by default in all CKEditor 4 LTS versions. Therefore, if you use CKEditor 4 LTS, it is highly unlikely that you are affected by this vulnerability. If you are unsure, please contact us. The fix is available in version 4.25.0-lts. |
Github GHSA |
GHSA-6v96-m24v-f58j | CKEditor4 low-risk cross-site scripting (XSS) vulnerability linked to potential domain takeover |
Ubuntu USN |
USN-7258-1 | CKEditor vulnerabilities |
Thu, 22 Aug 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 21 Aug 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A theoretical vulnerability has been identified in CKEditor 4.22 (and above). In a highly unlikely scenario where an attacker gains control over the https://cke4.ckeditor.com domain, they could potentially execute an attack on CKEditor 4 instances. The issue impacts only editor instances with enabled version notifications. Please note that this feature is disabled by default in all CKEditor 4 LTS versions. Therefore, if you use CKEditor 4 LTS, it is highly unlikely that you are affected by this vulnerability. If you are unsure, please contact us. The fix is available in version 4.25.0-lts. | |
| Title | CKEditor4 has a low risk cross-site scripting (XSS) vulnerability from domain takeover | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-22T13:51:02.904Z
Reserved: 2024-08-12T18:02:04.967Z
Link: CVE-2024-43411
Updated: 2024-08-22T13:50:58.562Z
Status : Deferred
Published: 2024-08-21T16:15:08.570
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-43411
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA
Ubuntu USN