Cross-site scripting in CKEditor - CVE-2022-24728

 

Cross-site scripting in CKEditor - CVE-2022-24728

Published: March 17, 2022


Vulnerability identifier: #VU61426
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2022-24728
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data in the core HTML processing module. A remote attacker can inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Affected software

CKEditor
Backdrop CMS
Drupal
Moodle
IBM Sterling B2B Integrator
Engineering Workflow Management
Fedora
Ubuntu
IBM Engineering Requirements Management DOORS Next
IBM Planning Analytics Workspace
IBM OpenPages with Watson
ckeditor (Ubuntu package)
ckeditor
IBM Cognos Analytics

How to mitigate CVE-2022-24728

Install updates from vendor's website.

CKEditor - update to 4.18.0
Backdrop CMS - addressed in versions 1.20.7, 1.21.4
Moodle - addressed in versions 3.9.13, 3.10.10, 3.11.6
IBM Sterling B2B Integrator - addressed in versions 6.0.3.7, 6.1.0.6, 6.1.1.2, 6.1.2.1, 6.1.2.6, 6.2.0.3
Drupal - addressed in versions 9.2.15, 9.3.8
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
ckeditor (Ubuntu package) - addressed in versions Ubuntu Pro, 4.22.1+dfsg1-2ubuntu0.24.10.1
IBM Planning Analytics Workspace - update to 2.0.83
ckeditor - addressed in versions 4.20.0-1.el7, 4.20.0-1.fc36, 4.20.0-1.fc37
Engineering Workflow Management - addressed in versions 7.0.1 iFix021, 7.0.2 iFix021
IBM OpenPages with Watson - update to 8.3.0.2
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 7, 11.2.4.1 IF1

External References

Related Security Bulletins