Description
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Maps-Display Google Maps Perfectly with Ease Cross-Site Scripting (4.0.3)
WordPress Plugin oQey Headers 'oqey_settings.php' SQL Injection (0.3)
Oracle JRE CVE-2023-21835 Vulnerability (CVE-2023-21835)
Drupal Core 7.x Multiple Vulnerabilities (7.0 - 7.34)
WordPress Plugin Print My Blog-Print, PDF, & eBook Converter Server-Side Request Forgery (1.6.5)