CVE-2020-9440
10.03.2020, 17:15
A cross-site scripting (XSS) vulnerability in the WSC plugin through 5.5.7.5 for CKEditor 4 allows remote attackers to run arbitrary web script inside an IFRAME element by injecting a crafted HTML element into the editor.
| Vendor | Product | Version |
|---|---|---|
| ckeditor | ckeditor | 4.0 |
| webspellchecker | webspellchecker | 𝑥 ≤ 5.5.7.5 |
𝑥
= Vulnerable software versions
Ubuntu Releases
References