Cross-site scripting in CKEditor - CVE-2021-32809

 

Cross-site scripting in CKEditor - CVE-2021-32809

Published: August 16, 2021


Vulnerability identifier: #VU55860
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2021-32809
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data. A remote authenticated attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Affected software

CKEditor
IBM Sterling B2B Integrator
Engineering Workflow Management
Fedora
Ubuntu
ckeditor (Ubuntu package)
ckeditor
Engineering Test Management
IBM Engineering Requirements Management DOORS Next

How to mitigate CVE-2021-32809

Install updates from vendor's website.

CKEditor - update to 4.16.2
IBM Sterling B2B Integrator - addressed in versions 6.0.3.7, 6.1.0.6, 6.1.1.2, 6.1.2.1, 6.1.2.6, 6.2.0.3
ckeditor (Ubuntu package) - addressed in versions 4.5.7+dfsg-2ubuntu0.18.04.1, 4.12.1+dfsg-1ubuntu0.1, 4.16.0+dfsg-2ubuntu0.1
ckeditor - addressed in versions 4.16.2-1.el7, 4.16.2-1.fc33, 4.16.2-1.fc34, 4.16.2-1.fc35
Engineering Workflow Management - addressed in versions 7.0.1 iFix021, 7.0.2 iFix021
Engineering Test Management - addressed in versions 7.0.1.0.23, 7.0.2.0.24
IBM Engineering Requirements Management DOORS Next - update to 7.0.2 ifix 32

External References

Related Security Bulletins