← Terug naar CVE-database
Beschrijving
A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.
Affected products
Ckeditor
Agile Product Lifecycle Management
Application Express
Banking Party Management
Banking Platform
Commerce Merchandising
Financial Services Analytical Applications Infrastructure
Jd Edwards Enterpriseone Tools
Peoplesoft Enterprise Peopletools