PT-2021-24351 · Tinymce · Tinymce
Yakir6
·
Published
2021-11-02
·
Updated
2025-11-28
·
CVE-2024-21910
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
TinyMCE versions prior to 5.10.0
Description:
A cross-site scripting vulnerability was discovered in the URL processing logic of the
image and link plugins, allowing arbitrary JavaScript execution when updating an image or link using a specially crafted URL. This issue only impacts users while editing, and the dangerous URLs are stripped in any content extracted from the editor.Recommendations:
To resolve the issue, either:
- Upgrade to TinyMCE 5.10.0 or higher
- Disable the
imageandlinkplugins as a temporary workaround until a patch is available.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tinymce