Security Research

CVE-2020-981 CKEditor 4 XSS: Sanitizer Boundaries in Rich Text Editors

#Vulnerability Analysis#Code Audit#Web Security
CKEditor 4 form overlay and javascript: XSS

CKEditor 4’s sanitizer has a gap in handling certain HTML tag-attribute combinations prior to v4.13 — a single crafted HTML snippet is enough to inject Stored XSS into every application that uses CKEditor 4.

Unlock to view this content.