Cross-site scripting (XSS) vulnerability in the Preview plugin before 4.4.3 in CKEditor allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
| Software | From | Fixed in |
|---|---|---|
ckeditor / ckeditor
|
4.4.1 | 4.4.1.x |
ckeditor / ckeditor
|
4.4.0 | 4.4.0.x |
ckeditor / ckeditor
|
- | 4.4.2.x |