CKEditor: HTML processing module CVE-2022-24728 

Issue date: 29-06-2022
Affects versions: 15.0, 14.7, 13.4

Security Issue ID

SECURITY-315

 

Affected Product Version(s)

13.4.17, 15.0.1, 14.7.7 and all previous versions


Severity 

medium/high


Description

CVE-2022-24728

A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. This problem has been patched in version 4.18.0. There are currently no known workarounds.

Instructions

Update to the latest version.