Forum Discussion

ManinderSingh03's avatar
ManinderSingh03
Copper Contributor
Sep 12, 2025

VAPT issue raised for CKEditor 4.13.0 Cross-Site Scripting

URL to JS file: https://testsite.com/_layouts/15/16.0.18526.20508/next/spclient/43.sp-canvas-sp-ckeditor-flight.js

 

Associating Common Weakness Enumeration (CWE)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CWE 79)

 

Evidence(s)

 

 

Steps to derive Evidence(s)

1.     Request to CKEditor File

2.     Reponse indicating the version

 

Recommendation(s)

Upgrade CKEditor to the latest version 4.25.1-lts for extended support on the package.

 

As this JS file is a part of SharePoint itself, cannot upgrade explicitly. Can anyone share the mitigation or plan to get it fixed except until Microsoft releases an update for same. 

 

No RepliesBe the first to reply

Resources