CVE-2023-4771
A Cross-Site scripting vulnerability has been found in CKSource CKEditor affecting versions 4.15.1 and earlier. An attacker could send malicious javascript code through the /ckeditor/samples/old/ajax.html file and retrieve an authorized user's information.
- Cksource Ckeditor
- ≤ 4.15.1
- Fix
- Available
- CVSS 3.1
- 6.1 MEDIUM
- EPSS
- 0.9% (56th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2023-11-16
- Attack patterns
- CAPEC-63
CVE-2023-4771 at NVD
1 known exploit for CVE-2023-4771
Proof-of-concept code and exploit modules indexed by Sploitus