Cross-site scripting vulnerability in TinyMCE - tinymce - GHSA-27gm-ghr9-4v95
- Severity:
- High
Description
A cross-site scripting (XSS) vulnerability was discovered in: the core parser, paste and visualchars plugins. The vulnerability allowed arbitrary JavaScript execution when inserting a specially crafted piece of content into the editor via the clipboard or APIs. This impacts all users who are using TinyMCE 4.9.6 or lower and TinyMCE 5.1.
Recommendation
Update the tinymce package to the latest compatible version. Followings are version details:
Affected version(s): **>= 5.0.0, < 5.1.4 < 4.9.7** Patched version(s): **5.1.4 4.9.7**
References
- GHSA-27gm-ghr9-4v95
- portswigger.net
- www.tiny.cloud
- CVE-2020-17480
- CWE-79
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- Cross-site scripting vulnerability in TinyMCE - tinymce - GHSA-vrv8-v4w8-f95h - CVE-2020-12648
- Cross-site Scripting in Joplin - joplin - GHSA-6r7x-hc8m-985r - CVE-2020-9038
- Bootstrap Cross-site Scripting vulnerability - bootstrap - GHSA-pj7m-g53m-7638 - CVE-2018-14041
- Cross-site scripting vulnerability in TinyMCE - tinymce - GHSA-5vm8-hhgr-jcjp - Vulnerability
You might also like:
- Tags:
- npm
- tinymce
Anything's wrong? Let us know Last updated on June 27, 2023


