Check: 2014-A-0116
Windows 2012 IAVM:
2014-A-0116
(in version v1 r30)
Title
CKEditor Cross-Site Scripting Vulnerability (Cat I impact)
Discussion
CKEditor has addressed a vulnerability in CKeditor. CKEditor (formerly FCKeditor) is an HTML text editor used in web pages. To exploit this vulnerability, a remote attacker would entice a user to follow a malicious URI sent via email. If successfully exploited, this vulnerability would allow a remote attacker to perform cross-site scripting attacks and compromise the affected system.
Check Content
Fix Text
Additional Identifiers
Rule ID:
Vulnerability ID: V-53503
Group Title:
Expert Comments
Expert comments are only available to logged-in users.
CCIs
CCIs tied to check.
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Controls tied to check. These are derived from the CCIs shown above.
Number | Title |
---|---|
No controls are assigned to this check |