CVE-2020-9440
10.03.2020, 17:15
A cross-site scripting (XSS) vulnerability in the WSC plugin through 5.5.7.5 for CKEditor 4 allows remote attackers to run arbitrary web script inside an IFRAME element by injecting a crafted HTML element into the editor.
Vendor | Product | Version |
---|---|---|
ckeditor | ckeditor | 4.0 |
webspellchecker | webspellchecker | 𝑥 ≤ 5.5.7.5 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References