CKEditor Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2020-9440 - Vulnerability Database

CKEditor Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2020-9440

Medium
Reference: CVE-2020-9440
Title: CKEditor Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

A cross-site scripting (XSS) vulnerability in the WSC plugin through 5.5.7.5 for CKEditor 4 allows remote attackers to run arbitrary web script inside an IFRAME element by injecting a crafted HTML element into the editor.