CVE-2024-37888 – CKEditor 4 Open Link plugin XSS
netspi.com | vulnerability | CVE-2024-37888 | #web-security | #xss | #cve-2024-37888 | #ckeditor | #plugin-security
Summary
CVE-2024-37888 is an XSS in CKEditor 4's Open Link plugin that lets crafted hyperlinks execute JavaScript in a victim's browser. Found during a client engagement, it affects latest plugin versions.
- CVE
- CVE-2024-37888
- Published
- Collected
Skip to content