Updated CKEditor 4 library to the latest 4.24.0-lts. This version of the editor includes important security patches. From now on, all versions below 4.24.0-lts can no longer be considered as secure.

See CKEditor 4 LTS - WYSIWYG HTML editor - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024-009.

Security Updates:

Cross-site scripting (XSS) vulnerability caused by incorrect CDATA detection reported by Michal Frýba, ALEF NULA.
Issue summary: The vulnerability allowed to inject malformed HTML content bypassing Advanced Content Filtering mechanism, which could result in executing JavaScript code. See GHA for more details.

Cross-site scripting (XSS) vulnerability in AJAX sample reported by Rafael Pedrero, see INCIBE report.
Issue summary: The vulnerability allowed to execute JavaScript code by abusing the AJAX sample. See GHA for more details.

Cross-site scripting (XSS) vulnerability in samples with enabled the preview feature reported by Marcin Wyczechowski & Michał Majchrowicz, AFINE Team.
Issue summary: The vulnerability allowed to execute JavaScript code by abusing the misconfigured preview feature. See GHA for more details.

If you use the CKEditor LTS module v1.0.0, upgrade to v1.0.1

VCS Label
1.0.1
Release type
Short description
Updated CKEditor library version due to it's vulnerabilities.
Packaged Git sha1
3e74f393c7a36762b352d6fe93c7ca649b5cde6f
Release files
9c012de5ed5fae705c4b53498e199eae
Release file SHA-1 hash
3b1ab93c3837ff7840ab323048168a95a4415570
Release file SHA-256 hash
0d7d3235f9f8f64d89d375c2f94520dee974379eed098760ac10b308256085b5
871d6685565c52e13d055999db323805
Release file SHA-1 hash
f16aba8f011fc58f43a3428b3cdb4ed669a02e2e
Release file SHA-256 hash
4f91cf9c5e50a874469c97cb827c2ea34064ea649d22fd59a626775bbd7e6be3