CVE-2023-37905
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Jul 21, 2023
Updated: Sep 15, 2023
CWE ID 79
Summary
CVE-2023-37905 is a cross-site scripting (XSS) vulnerability affecting the open-source WordCount Plugin for CKEditor, identified as 'ckeditor-wordcount-plugin'. This issue lies in the plugin's susceptibility to XSS attacks when users switch to the source code mode. The exploitation of this vulnerability could result in unintended code execution. Users are strongly advised to upgrade to version 1.17.12 of the plugin to mitigate this risk, as there are currently no known workarounds for this susceptibility.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share