#VU50055 Input validation error in CKEditor - CVE-2021-26271
Published: January 27, 2021
CKEditor
CKSource
Description
The vulnerability allows a remote attacker to perform a regular expression denial of service (ReDoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can trick the victim to paste a specially crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin) and perform a regular expression denial of service (ReDoS) attack.