Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q5pp-5q2h-g8rv

Опубликовано: 03 янв. 2024
Источник: github
Github: Прошло ревью

Описание

Duplicate Advisory: Cross-site scripting vulnerability in TinyMCE

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-5h9g-x5rv-25wg. This link is maintained to preserve external references.

Original Description

TinyMCE versions before 5.6.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting in arbitrary JavaScript execution in another user's browser.

Пакеты

Наименование

tinymce

npm
Затронутые версииВерсия исправления

Отсутствует

Дефекты

CWE-79

Дефекты

CWE-79