Executive brief
CKEditor 4 is a rich-text editor component used in web applications to allow users to create and edit formatted content. A vulnerability in its HTML processing module allows attackers to bypass content sanitization by injecting malformed HTML comments, enabling arbitrary JavaScript execution within the editor context or in pages displaying untrusted content.
Technical details
CKEditor 4 versions prior to 4.17.0 contain a cross-site scripting (XSS) vulnerability in the core HTML processing module. The vulnerability stems from improper handling of malformed HTML comments during content sanitization. An attacker can craft malformed comment syntax to bypass the editor's content filters and inject executable JavaScript code. Attack requires either authenticated access to create/edit content in CKEditor 4 or user interaction (e.g., pasting or importing untrusted HTML). The vulnerability affects all CKEditor 4 plugins that rely on the core HTML processing. A patch is available in version 4.17.0.
Affected products
- CKSource CKEditor 4 < 4.17.0
Timeline
- 2021-11-17: disclosed
- 2021-11-17: patched: Fixed in version 4.17.0