Vulnerability Bulletins |
Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2018-003 |
|
| Affected software | Drupal |
|
Project: Drupal coreDate: 2018-April-18Security risk: Moderately critical 12∕25 AC:Complex/A:User/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Cross Site ScriptingDescription: CKEditor, a third-party JavaScript library included in Drupal core, has fixed a cross-site scripting (XSS) vulnerability. The vulnerability stemmed from the fact that it was possible to execute XSS inside CKEditor when using the image2 plugin (which Drupal 8 core also uses).We would like to thank the More info: https://www.drupal.org/sa-core-2018-003 |
|






