Description
A Cross-Site scripting vulnerability has been found in CKSource CKEditor affecting versions 4.15.1 and earlier. An attacker could send malicious javascript code through the /ckeditor/samples/old/ajax.html file and retrieve an authorized user's information.
Remediation
References
https://www.incibe.es/en/incibe-cert/notices/aviso/cross-site-scripting-vulnerability-cksource-ckeditor
Related Vulnerabilities
CVE-2018-19837 Vulnerability in npm package node-sass
CVE-2018-3721 Vulnerability in maven package org.webjars.npm:lodash.merge
CVE-2022-21803 Vulnerability in maven package org.webjars.npm:nconf
CVE-2019-13506 Vulnerability in npm package @nuxt/devalue
CVE-2020-36319 Vulnerability in maven package com.vaadin:flow-server