CKEditor Inclusion of Functionality from Untrusted Control Sphere Vulnerability - CVE-2021-26271 - Vulnerability Database

CKEditor Inclusion of Functionality from Untrusted Control Sphere Vulnerability - CVE-2021-26271

Medium
Reference: CVE-2021-26271
Title: CKEditor Inclusion of Functionality from Untrusted Control Sphere Vulnerability
Overview:

It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).