Description
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
Remediation
References
Related Vulnerabilities
ownCloud Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-3836)
phpMyFAQ Other Vulnerability (CVE-2005-3734)
Moodle Server-Side Request Forgery (SSRF) Vulnerability (CVE-2023-35133)
WordPress Plugin Async JavaScript Security Bypass (2.19.07.14)
WordPress Plugin Real-Time Find and Replace Cross-Site Request Forgery (3.9)