CVE-2020-9281 | CKeditor up to 4.13 HTML Data Processor Comment HTML injection (FEDORA-2020-261449d821)
A vulnerability marked as problematic has been reported in CKeditor up to 4.13. Affected by this issue is some unknown functionality of the component HTML Data Processor. Performing a manipulation as part of Comment results in HTML injection.
This vulnerability is reported as CVE-2020-9281. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.