Description
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
Remediation
References
Related Vulnerabilities
Internet Information Services Other Vulnerability (CVE-2000-0167)
Oracle JRE CVE-2013-1569 Vulnerability (CVE-2013-1569)
OpenSSL Cryptographic Issues Vulnerability (CVE-2019-1543)
WordPress Plugin WordPress Colorbox Lightbox Cross-Site Scripting (1.1.2)
WordPress Plugin Themify Portfolio Post Cross-Site Scripting (1.2.0)