Drupal CKEditor 3.0 - 3.6.2 - Persistent EventHandler XSS

Discussion in 'Security and Legal' started by AWS, Jan 18, 2012.

  1. AWS

    AWS Administrator Admin Talk Staff

    Joined:
    Feb 1, 2010
    Messages:
    1,616
    Likes Received:
    692
    Location:
    Joliet, IL U.S.A.
    First Name:
    Bob
    There is a bug in Drupals implementation of CKEditor which can lead to an admin running malicious code. Drupal is not the only software that uses CKEditor so this could affect other scripts like IPB, vBulletin and others.

    Read the full security bulletin
     

Share This Page