CVE-2024-45613
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2024-45613 is a Cross-Site Scripting (XSS) vulnerability affecting CKEditor 5, a popular JavaScript rich-text editor. Versions 40.0.0 and earlier, up to 43.1.1, are vulnerable. The issue lies in the clipboard package, allowing unauthorized JavaScript code execution when a user interacts with a specifically crafted content. This is possible only in installations with the Block Toolbar plugin enabled, and either the General HTML Support with unsafe markup enabled or the HTML Embed plugin activated. The vulnerability was addressed in version 43.1.1, and a workaround is to disable the block toolbar plugin.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- CKSource CKEditor5
Affected Vendors
- Ckeditor