CERT-In Vulnerability Note
CIVN-2021-0331
Cross Site Scripting Vulnerability in CKEditor library in Drupal
Original Issue Date:November 23, 2021
Severity Rating: MEDIUM
Software Affected
- Drupal version prior to Drupal 9.2.9
- Drupal version prior to Drupal 9.1.14
- Drupal version prior to Drupal 8.9.20
Overview
A Cross Site Scripting (XSS) vulnerability exists in CKEditor library in Drupal which allows an attacker to perform cross-site scripting (XSS) attacks and take full control of the targeted system.
Description
These vulnerabilities exist in Drupal CKEditor library for WYSIWYG editing due to insufficient sanitization of user-supplied data inprocessing HTML comments and insufficient sanitization of user-supplied data in advanced Content Filter (ACF) module. An attacker could exploit these vulnerabilities by injecting and executing arbitrary HTML code in users browser in context of vulnerable website.
Successful exploitation of these vulnerabilities could allow an attacker to perform cross-site scripting (XSS) attacks and take full control of the targeted system.
Note: Drupal 8 has reached its end of life.
Solution
Apply appropriate updates as mentioned in
https://www.drupal.org/sa-core-2021-011
References
Drupal
https://www.drupal.org/sa-core-2021-011
CVE Name
CVE-2021-41164
CVE-2021-41165
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|