Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qwvc-vq5g-8cxv

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The bbcode plugin in TinyMCE 3.5.8 does not properly enforce the TinyMCE security policy for the (1) encoding directive and (2) valid_elements attribute, which allows attackers to conduct cross-site scripting (XSS) attacks via application-specific vectors, as demonstrated using a textarea element.

The bbcode plugin in TinyMCE 3.5.8 does not properly enforce the TinyMCE security policy for the (1) encoding directive and (2) valid_elements attribute, which allows attackers to conduct cross-site scripting (XSS) attacks via application-specific vectors, as demonstrated using a textarea element.

EPSS

Процентиль: 73%
0.00755
Низкий

Связанные уязвимости

ubuntu
почти 12 лет назад

The bbcode plugin in TinyMCE 3.5.8 does not properly enforce the TinyMCE security policy for the (1) encoding directive and (2) valid_elements attribute, which allows attackers to conduct cross-site scripting (XSS) attacks via application-specific vectors, as demonstrated using a textarea element.

nvd
почти 12 лет назад

The bbcode plugin in TinyMCE 3.5.8 does not properly enforce the TinyMCE security policy for the (1) encoding directive and (2) valid_elements attribute, which allows attackers to conduct cross-site scripting (XSS) attacks via application-specific vectors, as demonstrated using a textarea element.

debian
почти 12 лет назад

The bbcode plugin in TinyMCE 3.5.8 does not properly enforce the TinyM ...

EPSS

Процентиль: 73%
0.00755
Низкий