THREAT OPS › Threat News › [NVD] CVE-2021-41164 (HIGH 8.2) — CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML bypassing content sanitization,
[NVD] CVE-2021-41164 (HIGH 8.2) — CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML bypassing content sanitization,
CVE-2021-41164 CVSS: 8.2 HIGH Published: 2021-11-17T19:15:08.913
CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. It af
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2021-41164cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2021-41164