Description
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
Remediation
References
Related Vulnerabilities
MyBB Other Vulnerability (CVE-2007-1963)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-2146)
WordPress Plugin WooCommerce Cross-Site Scripting (2.0.12)
Joomla! Core 1.7.0 Cross-Site Scripting (1.7.0)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-2165)