Описание
TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by improper SVG namespace scope handling in the sanitizer. A crafted payload using nested elements can bypass attribute sanitization and execute arbitrary JavaScript. This vulnerability is fixed in 7.1.0.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
EPSS
8.7 High
CVSS3
5.4 Medium
CVSS3
Дефекты
Связанные уязвимости
TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by improper SVG namespace scope handling in the sanitizer. A crafted payload using nested elements can bypass attribute sanitization and execute arbitrary JavaScript. This vulnerability is fixed in 7.1.0.
TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0 ...
TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs
EPSS
8.7 High
CVSS3
5.4 Medium
CVSS3