CVE-2024-45613

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Sep 25, 2024
Updated: Oct 1, 2024
CWE ID 79

Summary

CVE-2024-45613 is a Cross-Site Scripting (XSS) vulnerability affecting CKEditor 5, a popular JavaScript rich-text editor. Versions 40.0.0 and earlier, up to 43.1.1, are vulnerable. The issue lies in the clipboard package, allowing unauthorized JavaScript code execution when a user interacts with a specifically crafted content. This is possible only in installations with the Block Toolbar plugin enabled, and either the General HTML Support with unsafe markup enabled or the HTML Embed plugin activated. The vulnerability was addressed in version 43.1.1, and a workaround is to disable the block toolbar plugin.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • CKSource CKEditor5

Affected Vendors

  • Ckeditor