Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 7 min 99 bronnen 3 kritiek 1 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2021-26272

MEDIUM · 6.5 CVSS Gepubliceerd: CWE-829

Beschrijving

It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).

Vendors

Ckeditor Oracle

Affected products

Ckeditor Agile Product Lifecycle Management Application Express Banking Party Management Commerce Merchandising Financial Services Analytical Applications Infrastructure Financial Services Model Management And Governance Jd Edwards Enterpriseone Tools Siebel Ui Framework Webcenter Sites

References