Description
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
Remediation
References
Related Vulnerabilities
phpMyAdmin Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2011-2505)
WordPress Plugin MStore API-Create Native Android & iOS Apps On The Cloud Security Bypass (2.1.5)
WebLogic Improper Access Control Vulnerability (CVE-2016-5601)
Internet Information Services Other Vulnerability (CVE-2000-0126)
WordPress Plugin Download Shortcode Local File Inclusion (0.2.3)