A Cross-Site scripting vulnerability has been found in CKSource CKEditor affecting versions 4.15.1 and earlier. An attacker could send malicious javascript code through the /ckeditor/samples/old/ajax.html file and retrieve an authorized user's information.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| ckeditor4(npm) | 0 | 4.24.0-lts | N/A |
CVSS Metrics