Описание
Duplicate Advisory: Cross-site scripting in TinyMCE
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-27gm-ghr9-4v95. This link is maintained to preserve external references.
Original Description
TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by using the clipboard or APIs to insert content into the editor.
Пакеты
Наименование
tinymce
npm
Затронутые версииВерсия исправления
< 4.9.7
4.9.7
Наименование
tinymce
npm
Затронутые версииВерсия исправления
>= 5.0.0, < 5.1.4
5.1.4
6.1 Medium
CVSS3
Дефекты
CWE-79
6.1 Medium
CVSS3
Дефекты
CWE-79