#VU78394 Cross-site scripting in CKEditor - CVE-2023-28439
Published: July 19, 2023 / Updated: September 6, 2023
CKEditor
CKSource
Description
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data within the Iframe Dialog and Media Embed packages. A remote user can inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.