CVE-2023-4771


Cross-Site Scripting vulnerability in CKSource CKEditor

A Cross-Site scripting vulnerability has been found in CKSource CKEditor affecting versions 4.15.1 and earlier. An attacker could send malicious javascript code through the /ckeditor/samples/old/ajax.html file and retrieve an authorized user's information.



We have discovered 6,542 live websites that are affected by CVE-2023-4771.

Contact us to get more info




Affected Software

Product  CKEditor
Category Rich Text Editors
Vulnerable Versions
  • from 0 through 4.15.1
Total Vulnerable Versions233
Vulnerable Domains6,542 live websites (78.36% of CKEditor install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-4771 and the relative popularity of websites


Details

  • Published - Nov 16, 2023
  • Updated - Nov 16, 2023

Credits

  • Rafael Pedrero (finder)





Countries

United States2,269 websites



New Zealand536 websites
Russia411 websites
France336 websites
Germany262 websites
India167 websites
Turkey163 websites
GB144 websites
Spain140 websites
Brazil131 websites

TLDs

.com2,451 websites
.org394 websites
.net363 websites
.ru307 websites
.fr144 websites
.com.br106 websites
.it93 websites
.de93 websites
.pl92 websites
.eu90 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-4771 through included software libraries and plugins.



References


Websites affected by CVE-2023-4771

Top websites that are affected by CVE-2023-4771. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
*****.net Netherlands**,***
***.******.**.nz New Zealand**,***
***.********.org United States**,***
*******.***.ua Ukraine**,***
***.*********.com France**,***
************.com United States**,***
****.*****.edu United States**,***
*****************.org United States**,***
******.org France**,***
*******.***.ua Ukraine**,***
See full domain list