major
minor
major
minor
You must update to at least version 4.18.0 due to a vulnerability in the previous version:
CVSSv3: MEDIUM, score: 5.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
CKEditor4 is an open-source WYSIWYG HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows an attacker to inject malformed HTML, bypassing content sanitization, which could result in the execution of JavaScript code. This issue has been patched in version 4.18.0. There are currently no known workarounds.
Improvement
Implementation of the latest version (currently 4.19.1) from the website https://ckeditor.com/ckeditor-4/download/ using the existing build-config.js file to ensure that all corresponding plugins are reinstalled.
Test
- Check whether the HTML editor still works in the application.