In CiviCRM before 5.28.1 and CiviCRM ESR before 5.27.5 ESR, the CKEditor configuration form allows CSRF.
{
"severity": "Medium",
"cpes": [
"cpe:2.3:a:civicrm:civicrm:*:*:*:*:-:*:*:*",
"cpe:2.3:a:civicrm:civicrm:*:*:*:*:extended_security_release:*:*:*"
]
}