Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Yakir6

#42806of 53,632
6.1Total CVSS
Vulnerabilities · 1
PT-2021-24351
6.1
2021-11-02
Tinymce · Tinymce · CVE-2024-21910
Name of the Vulnerable Software and Affected Versions: TinyMCE versions prior to 5.10.0 Description: A cross-site scripting vulnerability was discovered in the URL processing logic of the `image` and `link` plugins, allowing arbitrary JavaScript execution when updating an image or link using a specially crafted URL. This issue only impacts users while editing, and the dangerous URLs are stripped in any content extracted from the editor. Recommendations: To resolve the issue, either: - Upgrade to TinyMCE 5.10.0 or higher - Disable the `image` and `link` plugins as a temporary workaround until a patch is available.