Description
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2013-2454 Vulnerability (CVE-2013-2454)
Internet Information Services Other Vulnerability (CVE-1999-0253)
WordPress Plugin All-In-One Security (AIOS)-Security and Firewall Cross-Site Scripting (3.9.7)
WordPress Plugin Car Rental by BestWebSoft Cross-Site Scripting (1.0.4)
TYPO3 Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-3664)