Security News > 2020 > March > Drupal Updates CKEditor to Patch XSS Vulnerabilities

Drupal Updates CKEditor to Patch XSS Vulnerabilities
2020-03-19 19:21

The developers of the Drupal content management system announced on Wednesday that updates for versions 8.8.x and 8.7.x address a couple of vulnerabilities affecting the CKEditor library.

Drupal uses CKEditor and it has decided to update it to version 4.14, which patches two cross-site scripting vulnerabilities affecting earlier versions of the library.

"Vulnerabilities are possible if Drupal is configured to use the WYSIWYG CKEditor for your site's users. When multiple people can edit content, the vulnerability can be used to execute XSS attacks against other people, including site admins with more access," Drupal said in an advisory.

Drupal 7 is not affected, but website administrators using this version should still ensure that CKEditor has been updated to version 4.14 or higher, Drupal developers said.

While Drupal is not as targeted as WordPress, some of the vulnerabilities discovered in the past years were exploited at some point to hijack websites.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/BX-6dBMIN4Q/drupal-updates-ckeditor-patch-xss-vulnerabilities

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Drupal 135 209 503 90 16 818
Ckeditor 13 0 27 1 1 29