A reflected cross-site scripting (XSS) vulnerability in CKeditor v46.1.0 & Angular v18.0.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Angular Angular
cpe:2.3:a:angular:angular:18.0.0:-:*:*:*:node.js:*:*
|
— | — |
|
Ckeditor Ckeditor5
cpe:2.3:a:ckeditor:ckeditor5:46.1.0:*:*:*:*:*:*:*
|
— | — |