Executive brief
CKEditor is a rich-text editor used in many web applications to allow users to create and edit formatted content. A vulnerability in the Widget plugin's undo feature allows an attacker to inject and execute malicious JavaScript code by submitting specially crafted HTML. This could enable attackers to steal user sessions, deface content, or harvest sensitive information from users interacting with the editor.
Technical details
The vulnerability is a cross-site scripting (CWE-79) flaw in the CKEditor 4 Widget plugin when used with the Undo feature. The root cause involves improper handling of malformed widget HTML during undo operations, allowing JavaScript code execution. The attack requires user interaction (users must undo an action containing malicious widget HTML) and network access to a CKEditor instance. An attacker can achieve arbitrary JavaScript execution in the context of the web page, leading to session hijacking, data theft, or defacement. The vulnerability affects CKEditor 4 versions 4.13.0 through 4.16.1, with a fix released in version 4.16.2.
Affected products
- CKSource CKEditor 4 4.13.0 to 4.16.1
Timeline
- 2021-08-12: disclosed: Vulnerability disclosed via GitHub Security Advisory
- 2021-08-23: advisory: GHSA-6226-h7ff-ch6c published
- 2021-08-13: patched: Fixed in CKEditor 4.16.2
References
- https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-6226-h7ff-ch6c
- https://github.com/ckeditor/ckeditor4
- https://github.com/ckeditor/ckeditor4/releases/tag/4.16.2
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NYA354LJP47KCVJMTUO77ZCX3ZK42G3T
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UVOYN2WKDPLKCNILIGEZM236ABQASLGW
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WAGNWHFIQAVCP537KFFS2A2GDG66J7XD