Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2020-9440
A cross-site scripting (XSS) vulnerability in the WSC plugin through 5.5.7.5 for CKEditor 4 allows remote attackers to run arbitrary web script inside an IFRAME element by injecting a crafted HTML element into the editor.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.005
EPSS Ranking
64.1%
CVSS Severity
CVSS v3 Score
6.1
CVSS v2 Score
4.3
References
https://ckeditor.com/blog/CKEditor-4.14-with-Paste-from-LibreOffice-released/#security-issues-fixed
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7OJ4BSS3VEAEXPNSOOUAXX6RDNECGZNO/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L322YA73LCV3TO7ORY45WQDAFJVNKXBE/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M4HHYQ6N452XTCIROFMJOTYEUWSB6FR4/
https://ckeditor.com/blog/CKEditor-4.14-with-Paste-from-LibreOffice-released/#security-issues-fixed
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7OJ4BSS3VEAEXPNSOOUAXX6RDNECGZNO/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L322YA73LCV3TO7ORY45WQDAFJVNKXBE/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M4HHYQ6N452XTCIROFMJOTYEUWSB6FR4/
Products affected by CVE-2020-9440
Ckeditor
»
Ckeditor
»
Version:
4.0
cpe:2.3:a:ckeditor:ckeditor:4.0
Webspellchecker
»
Webspellchecker
»
Version:
5.5.4
cpe:2.3:a:webspellchecker:webspellchecker:5.5.4
Webspellchecker
»
Webspellchecker
»
Version:
5.5.4.1
cpe:2.3:a:webspellchecker:webspellchecker:5.5.4.1
Webspellchecker
»
Webspellchecker
»
Version:
5.5.4.2
cpe:2.3:a:webspellchecker:webspellchecker:5.5.4.2
Webspellchecker
»
Webspellchecker
»
Version:
5.5.4.3
cpe:2.3:a:webspellchecker:webspellchecker:5.5.4.3
Webspellchecker
»
Webspellchecker
»
Version:
5.5.5
cpe:2.3:a:webspellchecker:webspellchecker:5.5.5
Webspellchecker
»
Webspellchecker
»
Version:
5.5.6
cpe:2.3:a:webspellchecker:webspellchecker:5.5.6
Webspellchecker
»
Webspellchecker
»
Version:
5.5.7
cpe:2.3:a:webspellchecker:webspellchecker:5.5.7
Webspellchecker
»
Webspellchecker
»
Version:
5.5.7.1
cpe:2.3:a:webspellchecker:webspellchecker:5.5.7.1
Webspellchecker
»
Webspellchecker
»
Version:
5.5.7.2
cpe:2.3:a:webspellchecker:webspellchecker:5.5.7.2
Webspellchecker
»
Webspellchecker
»
Version:
5.5.7.3
cpe:2.3:a:webspellchecker:webspellchecker:5.5.7.3
Webspellchecker
»
Webspellchecker
»
Version:
5.5.7.4
cpe:2.3:a:webspellchecker:webspellchecker:5.5.7.4
Webspellchecker
»
Webspellchecker
»
Version:
5.5.7.5
cpe:2.3:a:webspellchecker:webspellchecker:5.5.7.5
Fedoraproject
»
Fedora
»
Version:
30
cpe:2.3:o:fedoraproject:fedora:30
Fedoraproject
»
Fedora
»
Version:
31
cpe:2.3:o:fedoraproject:fedora:31
Fedoraproject
»
Fedora
»
Version:
32
cpe:2.3:o:fedoraproject:fedora:32
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved