Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
CVE's Videos

← Terug naar CVE-database

CVE-2020-27193

MEDIUM · 6.1 CVSS Gepubliceerd: CWE-79

Beschrijving

A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.

Vendors

Ckeditor Oracle

Affected products

Ckeditor Agile Product Lifecycle Management Application Express Banking Party Management Banking Platform Commerce Merchandising Financial Services Analytical Applications Infrastructure Jd Edwards Enterpriseone Tools Peoplesoft Enterprise Peopletools

References