Junglewise Threat Intelligence

CVE-2024-24815: CKEditor4 cross-site scripting in HTML parsing with incorrect CDATA detection

CVE-2024-24815 · Severity: low · CVSS 3.1 · Published 2024-02-07

Technologies: ckeditor4 (npm), ckeditor/ckeditor (Packagist). Vendors: npm, Packagist.

Executive brief

CKEditor4 is a popular web-based rich text editor used in content management systems and web applications to allow users to create and edit formatted content. A cross-site scripting (XSS) vulnerability in its HTML parsing module allows attackers to inject malicious JavaScript code by exploiting faulty CDATA detection, potentially leading to account compromise, session hijacking, or data theft when the editor is used in full-page mode or with CDATA filtering enabled.

Technical details

The vulnerability is a cross-site scripting (CWE-79) flaw in CKEditor4's core HTML parsing module caused by incorrect CDATA element detection. An attacker can inject malformed HTML content that bypasses the Advanced Content Filtering (ACF) mechanism, allowing arbitrary JavaScript execution. The vulnerability affects all editor instances with full-page editing mode enabled or CDATA elements enabled in ACF configuration (which includes script and style elements by default). Exploitation requires user interaction (e.g., pasting or loading the malicious content into the editor), but does not require authentication. The vulnerability has been patched in version 4.24.0-lts (or 4.24.0 for Composer).

Affected products

  • CKSource CKEditor4 < 4.24.0-lts

Timeline

  • 2024-02-07: disclosed: Vulnerability disclosed via GitHub Security Advisory GHSA-fq6h-4g8v-qqvm
  • 2024-02-07: patched: Fix available in version 4.24.0-lts for npm and 4.24.0 for Composer

References

Related threats