PT-2021-24352 · Tinymce · Tinymce

Aaron Bishop

·

Published

2021-01-06

·

Updated

2025-06-11

·

CVE-2024-21911

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: TinyMCE versions prior to 5.6.0
Description: A stored cross-site scripting vulnerability was discovered in the URL sanitization logic of the core parser, allowing arbitrary JavaScript execution when inserting specially crafted content into the editor. This impacts all users using TinyMCE 5.5.1 or lower. An unauthenticated and remote attacker could insert crafted HTML into the editor, resulting in arbitrary JavaScript execution in another user's browser.
Recommendations: To resolve the issue, upgrade to TinyMCE 5.6.0 or higher. As a temporary workaround, manually sanitize iframe, object, and embed URL attributes using a TinyMCE node filter. Alternatively, disable iframe, object, and embed elements in your content using the invalid elements setting.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-21911
GHSA-Q5PP-5Q2H-G8RV
GHSA-W7JX-J77M-WP65

Affected Products

Tinymce