CVE-2020-9440

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
10/03/2020
Last modified:
07/11/2023

Description

A cross-site scripting (XSS) vulnerability in the WSC plugin through 5.5.7.5 for CKEditor 4 allows remote attackers to run arbitrary web script inside an IFRAME element by injecting a crafted HTML element into the editor.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ckeditor:ckeditor:4.0:*:*:*:*:*:*:*
cpe:2.3:a:webspellchecker:webspellchecker:*:*:*:*:*:*:*:* 5.5.7.5 (including)
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*