Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2021-33829
Description:A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!> is mishandled.
Test IDs: 1.3.6.1.4.1.25623.1.0.146108   1.3.6.1.4.1.25623.1.0.892813   1.3.6.1.4.1.25623.1.1.12.2022.5340.2   1.3.6.1.4.1.25623.1.0.112891   1.3.6.1.4.1.25623.1.0.112890   1.3.6.1.4.1.25623.1.0.117501  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2021-33829
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NYA354LJP47KCVJMTUO77ZCX3ZK42G3T/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UVOYN2WKDPLKCNILIGEZM236ABQASLGW/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WAGNWHFIQAVCP537KFFS2A2GDG66J7XD/
https://ckeditor.com/blog/ckeditor-4.16.1-with-accessibility-enhancements/#improvements-for-comments-in-html-parser
https://lists.debian.org/debian-lts-announce/2021/11/msg00007.html




© 1998-2025 E-Soft Inc. All rights reserved.