PT-2023-33068 · Tinymce · Tinymce
Published
2023-04-26
·
Updated
2023-04-26
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
TinyMCE versions 4.9.10 and earlier
TinyMCE versions 5.4.0 and earlier
Description
A cross-site scripting (XSS) issue was found in the core parser of TinyMCE, allowing arbitrary JavaScript execution when inserting specially crafted content into the editor via the clipboard or APIs.
Recommendations
For TinyMCE versions 4.9.10 and earlier, update to a version higher than 4.9.10 to resolve the issue.
For TinyMCE versions 5.4.0 and earlier, update to a version higher than 5.4.0 to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tinymce