Executive brief
CKEditor 4 is a rich-text editor used in web applications to allow users to create and format HTML content. A cross-site scripting (XSS) vulnerability in the Color Dialog and Color History features allows attackers to inject malicious JavaScript code that executes in a user's browser if the user pastes crafted HTML. This could lead to theft of session cookies, account takeover, or defacement of content.
Technical details
This is a classic cross-site scripting (XSS) vulnerability (CWE-79) in CKEditor 4's Color Dialog and Color History features. The root cause is improper neutralization of user-supplied HTML input during web page generation. An attacker must socially engineer a user into copying and pasting malicious HTML code into the Color Button dialog or related color input fields. The attack requires user interaction (paste action) and network reachability; no authentication is required. Upon successful exploitation, the attacker can execute arbitrary JavaScript in the context of the application, potentially stealing credentials, session tokens, or modifying page content. The vulnerability was patched in CKEditor 4.15.1, released in November 2020. CKEditor 4 reached end-of-life in June 2023, and security updates are only available through the Extended Support Model Package.
Affected products
- CKEditor CKEditor 4 <= 4.15.0
Timeline
- 2020-11-12: disclosed: Vulnerability disclosed and reported to NVD
- 2020-11-09: patched: Fixed in CKEditor 4.15.1 released November 9, 2020
- 2022-05-24: advisory: GitHub advisory GHSA-4m44-5j2g-xf64 published
References
- https://ckeditor.com/blog/CKEditor-4.15.1-with-a-security-patch-released
- https://ckeditor.com/cke4/release/CKEditor-4.15.1
- https://ckeditor.com/ckeditor-4/download
- https://github.com/ckeditor/ckeditor4
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://www.oracle.com/security-alerts/cpuApr2021.html