Moderate severityNVD Advisory· Published Jul 21, 2023· Updated Oct 21, 2024
Cross-site Scripting (XSS) in Source Mode of Editor in ckeditor-wordcount-plugin
CVE-2023-37905
Description
ckeditor-wordcount-plugin is an open source WordCount Plugin for CKEditor. It has been discovered that the ckeditor-wordcount-plugin plugin for CKEditor4 is susceptible to cross-site scripting when switching to the source code mode. This issue has been addressed in version 1.17.12 of the ckeditor-wordcount-plugin plugin and users are advised to upgrade. There are no known workarounds for this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ckeditor-wordcount-pluginnpm | < 1.17.12 | 1.17.12 |
Affected products
3- typo3/cms-rte-ckeditorv5Range: >= 10.0.0, < 10.4.39
- w8tcha/CKEditor-WordCount-Pluginv5Range: < 1.17.12
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-q9w4-w667-qqj4ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-37905ghsaADVISORY
- github.com/TYPO3/typo3/security/advisories/GHSA-m8fw-p3cr-6jqcghsaWEB
- github.com/w8tcha/CKEditor-WordCount-Plugin/commit/0f03b3e5b7c1409998a13aba3a95396e6fa349d8ghsax_refsource_MISCWEB
- github.com/w8tcha/CKEditor-WordCount-Plugin/commit/a4b154bdf35b3465320136fcb078f196b437c2f1ghsax_refsource_MISCWEB
- github.com/w8tcha/CKEditor-WordCount-Plugin/security/advisories/GHSA-q9w4-w667-qqj4ghsax_refsource_CONFIRMWEB
- typo3.org/security/advisory/typo3-core-sa-2023-004ghsaWEB
News mentions
0No linked articles in our index yet.