CKEditor 4 HTML Data Processor XSS Vulnerability

CKEditor 4 HTML Data Processor XSS Vulnerability

CVE-2021-33829 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!> is mishandled.

Learn more about our Web Application Penetration Testing UK.