We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-45400

CKEditor Open Link plugin vulnerable to Cross-site Scripting



Description

ckeditor-plugin-openlink is a plugin for the CKEditor JavaScript text editor that extends the context menu with a possibility to open a link in a new tab. A vulnerability in versions of the plugin prior to 1.0.7 allowed a user to execute JavaScript code by abusing the link href attribute. The fix is available starting with version 1.0.7.

Reserved 2024-08-28 | Published 2024-09-05 | Updated 2024-09-06 | Assigner GitHub_M


MEDIUM: 6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Problem types

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

< 1.0.7
affected

References

github.com/...enlink/security/advisories/GHSA-qj47-6x6q-m3c9

github.com/...ommit/402391fdd4d9cfd079031372f9caebbf54993ffb

cve.org (CVE-2024-45400)

nvd.nist.gov (CVE-2024-45400)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-45400

Support options

Helpdesk Chat, Email, Knowledgebase
Subscribe to our newsletter to learn more about our work.