The Open Link is a CKEditor plugin, extending context menu with a possibility to open link in a new tab. The vulnerability allowed to execute JavaScript code by abusing link href attribute. It affects all users using the Open Link plugin at version < **1.0.5**.
References
Configurations
No configuration.
History
14 Jun 2024, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-06-14 18:15
Updated : 2024-06-14 18:15
NVD link : CVE-2024-37888
Mitre link : CVE-2024-37888
CVE.ORG link : CVE-2024-37888
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
