Vulnerability Bulletins

Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2018-003

   
Affected software Drupal
 
Project: Drupal coreDate: 2018-April-18Security risk: Moderately critical 12∕25 AC:Complex/A:User/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Cross Site ScriptingDescription: CKEditor, a third-party JavaScript library included in Drupal core, has fixed a cross-site scripting (XSS) vulnerability. The vulnerability stemmed from the fact that it was possible to execute XSS inside CKEditor when using the image2 plugin (which Drupal 8 core also uses).We would like to thank the

More info:

https://www.drupal.org/sa-core-2018-003