Description
A cross-site scripting (XSS) vulnerability was discovered in the alert and confirm dialogs when these dialogs were provided with malicious HTML content. This can occur in plugins that use the alert or confirm dialogs, such as in the image plugin, which presents these dialogs when certain errors occur.
Recommendation
Update the tinymce package to the latest compatible version. Followings are version details:
Affected version(s): **< 5.10.7 >= 6.0.0, < 6.3.1** Patched version(s): **5.10.7 6.3.1**
References
Could your website be exposed too?
SmartScanner can check your website for Cross-site scripting vulnerability in TinyMCE alerts and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Cross-site scripting vulnerability in TinyMCE - tinymce - CVE-2024-21911
- Vuetify Cross-site Scripting vulnerability - CVE-2022-25873
- @dependencytrack/frontend vulnerable to Persistent Cross-Site-Scripting via Vulnerability Details - CVE-2022-39350
- CKEditor5 cross-site scripting vulnerability caused by the editor instance destroying process - @ckeditor/ckeditor5-markdown-gfm - CVE-2022-31175


