Cross-site scripting in CKEditor - CVE-2022-24728
Published: March 17, 2022
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data in the core HTML processing module. A remote attacker can inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
Backdrop CMS
Drupal
Moodle
IBM Sterling B2B Integrator
Engineering Workflow Management
Fedora
Ubuntu
IBM Engineering Requirements Management DOORS Next
IBM Planning Analytics Workspace
IBM OpenPages with Watson
ckeditor (Ubuntu package)
ckeditor
IBM Cognos Analytics
How to mitigate CVE-2022-24728
Backdrop CMS - addressed in versions 1.20.7, 1.21.4
Moodle - addressed in versions 3.9.13, 3.10.10, 3.11.6
IBM Sterling B2B Integrator - addressed in versions 6.0.3.7, 6.1.0.6, 6.1.1.2, 6.1.2.1, 6.1.2.6, 6.2.0.3
Drupal - addressed in versions 9.2.15, 9.3.8
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
ckeditor (Ubuntu package) - addressed in versions Ubuntu Pro, 4.22.1+dfsg1-2ubuntu0.24.10.1
IBM Planning Analytics Workspace - update to 2.0.83
ckeditor - addressed in versions 4.20.0-1.el7, 4.20.0-1.fc36, 4.20.0-1.fc37
Engineering Workflow Management - addressed in versions 7.0.1 iFix021, 7.0.2 iFix021
IBM OpenPages with Watson - update to 8.3.0.2
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 7, 11.2.4.1 IF1
External References
Related Security Bulletins
- Multiple vulnerabilities in CKEditor
- Drupal update for CKEditor library
- Backdrop CMS update for CKEditor library
- Moodle update for CKEditor
- Multiple vulnerabilities in IBM Sterling B2B Integrator
- Multiple vulnerabilities in IBM Planning Analytics Workspace
- Multiple vulnerabilities in IBM Engineering Workflow Management (EWM)
- Multiple vulnerabilities in IBM Cognos Analytics
- Multiple vulnerabilities in IBM OpenPages with Watson
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS/DWA
- IBM Sterling B2B Integrator update for CKEditor
- Fedora 36 update for ckeditor
- Fedora EPEL 7 update for ckeditor
- Fedora 37 update for ckeditor
- Ubuntu update for ckeditor