PT-2023-11640 · Tinymce · Tinymce

Published

2023-06-26

·

Updated

2024-05-14

·

CVE-2020-23066

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions TinyMCE versions 4.9.6 and earlier TinyMCE versions 5.0.0 through 5.1.4
Description The issue allows an attacker to execute arbitrary code via the editor function, which is related to a Cross Site Scripting vulnerability.
Recommendations For TinyMCE versions 4.9.6 and earlier, update to a version later than 4.9.6. For TinyMCE versions 5.0.0 through 5.1.4, update to a version later than 5.1.4.

Fix

Related Identifiers

CVE-2020-23066

Affected Products

Tinymce