Junglewise Threat Intelligence

CVE-2024-43411: CKEditor4 cross-site scripting via domain takeover

CVE-2024-43411 · Severity: low · CVSS 3.1 · Published 2024-08-21

Technologies: ckeditor4 (npm). Vendors: npm.

Executive brief

CKEditor4 is a popular rich-text editing component used in web applications. A theoretical cross-site scripting (XSS) vulnerability exists only if an attacker gains control of the ckeditor.com domain and the target instance has version notifications enabled (disabled by default). The risk is low because the domain takeover itself is an extremely unlikely prerequisite, and the feature is off by default in supported versions.

Technical details

CKEditor4 versions 4.22.0 and above contain an XSS vulnerability (CWE-79) that is contingent on external domain compromise. The vulnerability is only reachable if version notifications are explicitly enabled on the editor instance and an attacker successfully takes control of the https://cke4.ckeditor.com domain. Since version notifications are disabled by default in CKEditor 4 LTS releases, the exposure is minimal in practice. The vulnerability has been patched in version 4.25.0-lts. No active exploitation in the wild has been reported.

Affected products

  • CKSource CKEditor4 4.22.0 to 4.25.0-lts

Timeline

  • 2024-08-21: disclosed
  • 2024-08-21: patched: Fix available in CKEditor4 4.25.0-lts

References

Related threats