Vulnerabilities/

TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements

Severity:
Medium

Description

A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content parsing code. This allowed specially crafted noscript elements containing malicious code to be executed when that content was loaded into the editor.

Recommendation

Update the tinymce package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
tinymce
Anything's wrong? Let us know Last updated on August 04, 2024