• About
  • Advertise
  • Careers
  • Contact
Saturday, March 25, 2023
No Result
View All Result
NEWSLETTER
Cyber360 News
  • Home
  • Security
  • Data Breach
  • Cyber Attacks
  • Cyber Security
  • Cyber Crime
  • Contact Us
  • Home
  • Security
  • Data Breach
  • Cyber Attacks
  • Cyber Security
  • Cyber Crime
  • Contact Us
No Result
View All Result
Cyber360 News
No Result
View All Result
Home Security

Drupal addresses two XSS flaws by updating the CKEditor

by Cyber360 News
March 20, 2020
in Security
0
Drupal addresses two XSS flaws by updating the CKEditor
0
SHARES
4
VIEWS
Share on FacebookShare on Twitter

Drupal developers released security updates for versions 8.8.x and 8.7.x that fix two XSS vulnerabilities affecting the CKEditor library.

The Drupal development team has released security updates for versions 8.8.x and 8.7.x that address two XSS vulnerabilities that affect the CKEditor library.

CKEditoris the far superior successor of FCKeditor, it is a popular, highly configurable open-source WYSIWYG editor.

Drupal uses CKEditor, it has updated to version 4.14, which addressed two cross-site scripting (XSS) vulnerabilities.

“The Drupal project uses the third-party library CKEditor, which has released a security improvement that is needed to protect some Drupal configurations.” reads the advisory published by Drupal.

“Vulnerabilities are possible if Drupal is configured to use the WYSIWYG CKEditor for your site’s users. An attacker that can create or edit content may be able to exploit this Cross Site Scripting (XSS) vulnerability to target users with access to the WYSIWYG CKEditor, and this may include site admins with privileged access.”

Both issues have been rated as a moderately critical severity, they received a risk score of 13/25.

The latest versions of Drupal, versions 8.8.4 or 8.7.12, include CKEditor version 4.14 that fix both issues.

Drupal 8 versions prior to 8.7.x have reached end-of-life and will not receive security updates, Drupal 7 is not affected by the issue, but it is recommended the use of CKEditor version 4.14 or higher.

The risk of exploitation of the flaws could be mitigated by disabling the CKEditor module.

According to the release note published by CKEditor 4.14 the flaws are not easy to exploit.

For example, one of the XSS flaws affects the HTML data processor, it could be exploited by tricking the victims into pasting malicious HTML code into the editor, either in WYSIWYG mode or source mode.

The other issue impacts a third-party plugin named WebSpellChecker Dialog plugin that is included in the Standard and Full presets of CKEditor 4. This issue could be exploited by an attacker that tricks the victim into switching CKEditor to source mode, pasting malicious code, switching back to WYSIWYG mode, and previewing the content on a page where the WebSpellChecker Dialog plugin files are available.

Pierluigi Paganini

(SecurityAffairs – XSS, CKEditor)



Share On


Cyber360 News

Cyber360 News

Next Post
Another day, another Coronavirus related scam, thanks to opportunistic cybercriminals. 

Another day, another Coronavirus related scam, thanks to opportunistic cybercriminals. 

Recent Posts

Twitch’s Entire Critical Data Leaked, Includes Streamer Earnings, Source Code

Twitch’s Entire Critical Data Leaked, Includes Streamer Earnings, Source Code

October 6, 2021
Former U.S. Security Firm Helped The UAE Carry Out “Karma” iMessage Hack: MIT Tech Review

Former U.S. Security Firm Helped The UAE Carry Out “Karma” iMessage Hack: MIT Tech Review

October 1, 2021
Facing “This App Has Been Blocked For Your Protection” Issue? Here’s How You Can Fix It

Facing “This App Has Been Blocked For Your Protection” Issue? Here’s How You Can Fix It

October 1, 2021

Whats New in Kali Linux?

September 14, 2021

Kali Linux 2019.3 Release (CloudFlare, Kali-status, metapackages, Helper-Scripts & LXD)

September 14, 2021

Kali Linux 2021.3 Release (OpenSSL, Kali-Tools, Kali Live VM Support, Kali NetHunter Smartwatch)

September 14, 2021

Kali Linux 2018.4 Release

September 14, 2021

Kali Linux 1.0.5 and Software Defined Radio

September 14, 2021

Kali Tools Website Launched, 1.0.9 Release

September 14, 2021

Kali Linux Dojo at Black Hat Vegas 2016

September 14, 2021

Category

Site Links

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

About Us

We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Check our landing page for details.

© 2019 Cyber360 News - Powered by WebSensePro

No Result
View All Result
  • Home
  • Security
  • Data Breach
  • Cyber Attacks
  • Cyber Security
  • Cyber Crime
  • Contact Us

© 2019 Cyber360 News - Powered by WebSensePro

Login to your account below

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In