GHSA-6mjp-2rm6-9g85
CRITICALCVE-2023-22457The CKEditor.HTMLConverter document lacked a protection against Cross-Site Request Forgery (CSRF), allowing to execute macros with the rights of the current user. If a privileged user with programming rights was tricked into executing a GET request to this document with certain parameters (e.g., via an image with a corresponding URL embedded in a comment or via a redirect), this would allow arbitr
- Affected
- < 1.64.3
- Fixed in
- 1.64.3
- Published
- 2023-01-06
- Source
- github