Описание
TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in the media plugin. Attackers can inject malicious scripts via crafted data-mce-* attributes, which are executed when content is rendered. Impacts users of TinyMCE with the media plugin enabled. This vulnerability is fixed in 5.11.1, 7.9.3, and 8.5.1.
Ссылки
- PatchVendor Advisory
- Release Notes
- Release Notes
Уязвимые конфигурации
Одно из
EPSS
8.7 High
CVSS3
5.4 Medium
CVSS3
Дефекты
Связанные уязвимости
TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in the media plugin. Attackers can inject malicious scripts via crafted data-mce-* attributes, which are executed when content is rendered. Impacts users of TinyMCE with the media plugin enabled. This vulnerability is fixed in 5.11.1, 7.9.3, and 8.5.1.
TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, an ...
TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection
EPSS
8.7 High
CVSS3
5.4 Medium
CVSS3