CVE-2024-45400

ckeditor-plugin-openlink is a plugin for the CKEditor JavaScript text editor that extends the context menu with a possibility to open a link in a new tab. A vulnerability in versions of the plugin prior to 1.0.7 allowed a user to execute JavaScript code by abusing the link href attribute. The fix is available starting with version 1.0.7.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mlewand:open_link:*:*:*:*:*:ckeditor:*:*

History

19 Sep 2024, 18:04

Type Values Removed Values Added
CPE cpe:2.3:a:mlewand:open_link:*:*:*:*:*:ckeditor:*:*
References () https://github.com/mlewand/ckeditor-plugin-openlink/commit/402391fdd4d9cfd079031372f9caebbf54993ffb - () https://github.com/mlewand/ckeditor-plugin-openlink/commit/402391fdd4d9cfd079031372f9caebbf54993ffb - Patch
References () https://github.com/mlewand/ckeditor-plugin-openlink/security/advisories/GHSA-qj47-6x6q-m3c9 - () https://github.com/mlewand/ckeditor-plugin-openlink/security/advisories/GHSA-qj47-6x6q-m3c9 - Vendor Advisory
First Time Mlewand open Link
Mlewand

06 Sep 2024, 12:08

Type Values Removed Values Added
Summary
  • (es) ckeditor-plugin-openlink es un complemento para el editor de texto JavaScript CKEditor que amplía el menú contextual con la posibilidad de abrir un enlace en una nueva pestaña. Una vulnerabilidad en las versiones del complemento anteriores a la 1.0.7 permitía a un usuario ejecutar código JavaScript abusando del atributo href del enlace. La solución está disponible a partir de la versión 1.0.7.

06 Sep 2024, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-06 00:15

Updated : 2024-09-19 18:04


NVD link : CVE-2024-45400

Mitre link : CVE-2024-45400

CVE.ORG link : CVE-2024-45400


JSON object : View

Products Affected

mlewand

  • open_link
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')