19-Jun-2017 19:32

After reaching more than 3 million downloads, FCKeditor was completely reviewed and redesigned into CKEditor 3, with special attention given to performance, accessibility and a new UI.In December 2012, CKEditor 4 was released with an Inline Editing solution, reformatted source code, enhanced DOM and CSS performance. After 5 years, in 2017, CKEditor 5 Alpha was introduced.A custom collaborative solution can be build by using the CKEditor 5 Framework components and real-time collaborative editing can be enabled by connecting to the CKEditor Cloud Services.A ready to use, drop-in component based on CKEditor 5 (Letters) offers a complete solution for real-time collaborative writing.Description: A vulnerability was reported in FCKeditor.A remote user can upload arbitrary files to the target system.CKEditor (formerly known as FCKeditor) is a WYSIWYG rich text editor which enables writing content directly inside of web pages or online applications.Its core code is written in Java Script and it is developed by CKSource.

The input of several connector modules is not properly verified before being used, this leads to exposure of the contents of arbitrary directories on the server filesystem and allows file uploading to arbitrary locations.The affected code is remotely exposed before authentication.