{"id":"DRUPAL-CONTRIB-2024-009","details":"The CKEditor 4 LTS - WYSIWYG HTML editor module uses the CKEditor library for WYSIWYG editing. CKEditor has released a [security update](https://ckeditor.com/cke4/release/CKEditor-4.24.0-LTS) that on certain configurations may impact the Drupal module that bundles and integrates this code.\n\nThe vulnerability is mitigated by the fact it requires:\n\n1. [full-page editing](https://ckeditor.com/docs/ckeditor4/latest/features/fullpage.html) mode is enabled\n2. or CDATA elements in Advanced Content Filtering configuration (defaults to script and style elements) are enabled.\n3. An attacker must have a permission with access to the CKEditor instance.\n\nFor more information, see CKEditor's security advisory:  \n[CVE-2024-24815](https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-fq6h-4g8v-qqvm): Cross-site scripting (XSS) vulnerability caused by incorrect CDATA detection","aliases":["CVE-2024-13245"],"modified":"2026-09-10T03:45:35.923526658Z","published":"2024-02-14T19:31:10Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2024-009"}],"affected":[{"package":{"name":"drupal/ckeditor_lts","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/ckeditor_lts?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.0"},{"fixed":"1.0.1"}],"database_specific":{"constraint":"\u003e=1.0.0 \u003c1.0.1"}}],"database_specific":{"affected_versions":"\u003e=1.0.0 \u003c1.0.1","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/ckeditor_lts/DRUPAL-CONTRIB-2024-009.json"}}],"schema_version":"1.9.0","credits":[{"name":"Juraj Nemec","contact":["https://www.drupal.org/user/272316"]}]}