CKeditor: XSS vulnerabilities in the core module 

Issue date: 29-06-2022
Affects versions: 15.0, 14.7, 13.4

Security Issue ID

SECURITY-297

SECURITY-306

 

Affected Product Version(s)

13.4.17, 15.0.1, 14.7.7 and all previous versions


Severity 

medium/high


Description

CVE-2021-41165

CVE-2021-41164

The vulnerability allowed to inject malformed comments HTML bypassing content sanitization, which could result in executing JavaScript code. See security advisory for more details.

Instructions

Update to the latest version.