PT-2023-33068 · Tinymce · Tinymce

Published

2023-04-26

·

Updated

2023-04-26

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions TinyMCE versions 4.9.10 and earlier TinyMCE versions 5.4.0 and earlier
Description A cross-site scripting (XSS) issue was found in the core parser of TinyMCE, allowing arbitrary JavaScript execution when inserting specially crafted content into the editor via the clipboard or APIs.
Recommendations For TinyMCE versions 4.9.10 and earlier, update to a version higher than 4.9.10 to resolve the issue. For TinyMCE versions 5.4.0 and earlier, update to a version higher than 5.4.0 to resolve the issue.

Fix

Related Identifiers

GHSA-WQM8-JX8R-8RCQ

Affected Products

Tinymce