PT-2024-40085 · Tinymce · Tinymce

Published

2024-07-17

·

Updated

2024-07-17

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions: TinyMCE version 6
Description: The issue arises from a configuration value convert unsafe embeds set to false, allowing svg files with javascript to be used in <object> or <embed> tags, potentially leading to XSS attacks. Note that <embed> tags are not allowed by default. The vulnerability's impact is considered medium, given how TinyMCE is used within certain contexts.
Recommendations: For TinyMCE version 6, update the configuration value convert unsafe embeds to true to mitigate the risk. Alternatively, consider overriding this configuration if necessary, but be aware that this may introduce security risks. As a temporary workaround, consider restricting the use of <object> tags until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-52CW-PVQ9-9M5V

Affected Products

Tinymce