PT-2023-33068 · Tinymce · Tinymce

Publicado

2023-04-26

·

Atualizado

2023-04-26

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions TinyMCE versions 4.9.10 and earlier TinyMCE versions 5.4.0 and earlier
Description A cross-site scripting (XSS) issue was found in the core parser of TinyMCE, allowing arbitrary JavaScript execution when inserting specially crafted content into the editor via the clipboard or APIs.
Recommendations For TinyMCE versions 4.9.10 and earlier, update to a version higher than 4.9.10 to resolve the issue. For TinyMCE versions 5.4.0 and earlier, update to a version higher than 5.4.0 to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

GHSA-WQM8-JX8R-8RCQ

Produtos afetados

Tinymce