Miggo Logo

CVE-2021-26272:
Inclusion of Functionality from Untrusted Control Sphere in CKEditor 4

6.5

CVSS Score
3.1

Basic Information

EPSS Score
0.42874%
Published
10/13/2021
Updated
2/1/2023
KEV Status
No
Technology
TechnologyJavaScript

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Package NameEcosystemVulnerable VersionsFirst Patched Version
ckeditor4npm< 4.16.04.16.0

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

It w*s possi*l* to *x**ut* * R**oS-typ* *tt**k insi** *K**itor * ***or* *.** *y p*rsu**in* * vi*tim to p*st* *r**t** URL-lik* t*xt into t** **itor, *n* t**n pr*ss *nt*r or Sp*** (in t** *utolink plu*in).

Reasoning

No *n*lysis *v*il**l*