Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 6 min 98 bronnen 3 kritiek 34 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2021-26271

MEDIUM · 6.5 CVSS Gepubliceerd: CWE-829

Beschrijving

It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).

Vendors

Ckeditor Oracle

Affected products

Ckeditor Agile Product Lifecycle Management Application Express Financial Services Analytical Applications Infrastructure Jd Edwards Enterpriseone Tools Siebel Ui Framework Webcenter Sites

References