CVE-2020-27193

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
12/11/2020
Last modified:
02/12/2021

Description

A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ckeditor:ckeditor:4.15.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:agile_plm:9.3.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*
cpe:2.3:a:oracle:application_express:*:*:*:*:*:*:*:* 21.1.0.00.01 (excluding)
cpe:2.3:a:oracle:banking_party_management:2.7.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:banking_platform:2.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:banking_platform:2.7.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:banking_platform:2.7.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:banking_platform:2.8.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:banking_platform:2.9.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:commerce_merchandising:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:commerce_merchandising:11.1.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:commerce_merchandising:11.2.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:commerce_merchandising:11.3.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:commerce_merchandising:11.3.1:*:*:*:*:*:*:*