PT-2021-24352 · Tinymce · Tinymce
Aaron Bishop
·
Published
2021-01-06
·
Updated
2025-06-11
·
CVE-2024-21911
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
TinyMCE versions prior to 5.6.0
Description:
A stored cross-site scripting vulnerability was discovered in the URL sanitization logic of the core parser, allowing arbitrary JavaScript execution when inserting specially crafted content into the editor. This impacts all users using TinyMCE 5.5.1 or lower. An unauthenticated and remote attacker could insert crafted HTML into the editor, resulting in arbitrary JavaScript execution in another user's browser.
Recommendations:
To resolve the issue, upgrade to TinyMCE 5.6.0 or higher.
As a temporary workaround, manually sanitize
iframe, object, and embed URL attributes using a TinyMCE node filter.
Alternatively, disable iframe, object, and embed elements in your content using the invalid elements setting.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tinymce