CVE-2024-37888

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
14/06/2024
Last modified:
08/08/2024

Description

The Open Link is a CKEditor plugin, extending context menu with a possibility to open link in a new tab. The vulnerability allowed to execute JavaScript code by abusing link href attribute. It affects all users using the Open Link plugin at version

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mlewand:open_link:*:*:*:*:*:ckeditor:*:* 1.0.5 (excluding)