A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!> is mishandled.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T23:58:23.102Z
Reserved: 2021-06-03T00:00:00
Link: CVE-2021-33829

No data.

Status : Modified
Published: 2021-06-09T12:15:07.863
Modified: 2024-11-21T06:09:38.707
Link: CVE-2021-33829

No data.