Unknown
CVE-2021-41165
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2021-41165
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed comments HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0. The problem has been recognized and patched. The fix will be available in version 4.17.0.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
- ckeditor,
- drupal,
- oracle
Products
- agile product lifecycle management 9.3.6,
- application express,
- banking apis,
- banking apis 19.1,
- banking apis 19.2,
- banking apis 20.1,
- banking apis 21.1,
- banking digital experience,
- banking digital experience 19.1,
- banking digital experience 19.2,
- banking digital experience 20.1,
- banking digital experience 21.1,
- ckeditor,
- commerce guided search 11.3.2,
- drupal,
- peoplesoft enterprise peopletools 8.58,
- peoplesoft enterprise peopletools 8.59,
- webcenter portal 12.2.1.3.0,
- webcenter portal 12.2.1.4.0
References
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: