Vulnerability Description
A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ckeditor | Ckeditor | 4.15.0 |
| Oracle | Agile Plm | 9.3.5 |
| Oracle | Application Express | < 21.1.0.00.01 |
| Oracle | Banking Party Management | 2.7.0 |
| Oracle | Banking Platform | 2.4.0 |
| Oracle | Commerce Merchandising | 11.0.0 |
| Oracle | Financial Services Analytical Applications Infrastructure | >= 8.0.6, <= 8.0.9 |
| Oracle | Jd Edwards Enterpriseone Tools | < 9.2.6.0 |
| Oracle | Peoplesoft Enterprise Peopletools | 8.56 |
Related Weaknesses (CWE)
References
- https://ckeditor.com/blog/CKEditor-4.15.1-with-a-security-patch-released/Release NotesVendor Advisory
- https://ckeditor.com/cke4/release/CKEditor-4.15.1Release NotesVendor Advisory
- https://ckeditor.com/ckeditor-4/download/Release NotesVendor Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.htmlPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatchThird Party Advisory
- https://ckeditor.com/blog/CKEditor-4.15.1-with-a-security-patch-released/Release NotesVendor Advisory
- https://ckeditor.com/cke4/release/CKEditor-4.15.1Release NotesVendor Advisory
- https://ckeditor.com/ckeditor-4/download/Release NotesVendor Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.htmlPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatchThird Party Advisory
FAQ
What is CVE-2020-27193?
CVE-2020-27193 is a vulnerability with a CVSS score of 6.1 (MEDIUM). A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML cod...
How severe is CVE-2020-27193?
CVE-2020-27193 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-27193?
Check the references section above for vendor advisories and patch information. Affected products include: Ckeditor Ckeditor, Oracle Agile Plm, Oracle Application Express, Oracle Banking Party Management, Oracle Banking Platform.