MEDIUM 6.1 Packagist

Enhanced Image plugin for CKEditor is vulnerable to Cross-site scripting (XSS)

GHSA-g78h-pf65-46rv · CVE-2018-9861 · DRUPAL-CORE-2018-003

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

The Enhanced Image (aka image2) plugin for CKEditor in versions 4.5.10 through 4.9.1; fixed in 4.9.2, and as used in Drupal 8 before 8.4.7 and 8.5.x before 8.5.2 and other products, is vulnerable to cross-site scripting because it allows remote attackers to inject arbitrary web script through a crafted IMG element.

Ready to move

Start Securing

Free, no credit card | First findings in minutes