Cross-site scripting in CKEditor - CVE-2023-28439

 

Cross-site scripting in CKEditor - CVE-2023-28439

Published: July 19, 2023 / Updated: September 6, 2023


Vulnerability identifier: #VU78394
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2023-28439
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data within the Iframe Dialog and Media Embed packages. A remote user can inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.


Affected software

CKEditor
Oracle Banking Deposits and Lines of Credit Servicing
IBM Sterling B2B Integrator
IBM Sterling Control Center
Oracle Banking APIs
Oracle Analytics Desktop
Oracle Business Intelligence Enterprise Edition
Oracle Banking Digital Experience
Fedora
Ubuntu
Oracle Agile PLM Framework
Oracle Commerce Platform
Siebel Apps - Marketing
ckeditor (Ubuntu package)
ckeditor

How to mitigate CVE-2023-28439

Install updates from vendor's website.

CKEditor - update to 4.21.0
IBM Sterling B2B Integrator - addressed in versions 6.1.2.6, 6.2.0.3
IBM Sterling Control Center - update to 6.2.1.0.15
ckeditor (Ubuntu package) - addressed in versions Ubuntu Pro, 4.22.1+dfsg1-2ubuntu0.24.10.1
ckeditor - addressed in versions 4.22.1-1.el7, 4.22.1-1.fc37, 4.22.1-1.fc38, 4.22.1-1.fc39

External References

Related Security Bulletins