PT-2023-33068 · Tinymce · Tinymce
Publicado
2023-04-26
·
Atualizado
2023-04-26
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
TinyMCE versions 4.9.10 and earlier
TinyMCE versions 5.4.0 and earlier
Description
A cross-site scripting (XSS) issue was found in the core parser of TinyMCE, allowing arbitrary JavaScript execution when inserting specially crafted content into the editor via the clipboard or APIs.
Recommendations
For TinyMCE versions 4.9.10 and earlier, update to a version higher than 4.9.10 to resolve the issue.
For TinyMCE versions 5.4.0 and earlier, update to a version higher than 5.4.0 to resolve the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Tinymce