Логотип exploitDog
bind:CVE-2024-38356
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-38356

Количество 5

Количество 5

ubuntu логотип

CVE-2024-38356

больше 1 года назад

TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content extraction code. When using the `noneditable_regexp` option, specially crafted HTML attributes containing malicious code were able to be executed when content was extracted from the editor. This vulnerability has been patched in TinyMCE 7.2.0, TinyMCE 6.8.4 and TinyMCE 5.11.0 LTS by ensuring that, when using the `noneditable_regexp` option, any content within an attribute is properly verified to match the configured regular expression before being added. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2024-38356

больше 1 года назад

TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content extraction code. When using the `noneditable_regexp` option, specially crafted HTML attributes containing malicious code were able to be executed when content was extracted from the editor. This vulnerability has been patched in TinyMCE 7.2.0, TinyMCE 6.8.4 and TinyMCE 5.11.0 LTS by ensuring that, when using the `noneditable_regexp` option, any content within an attribute is properly verified to match the configured regular expression before being added. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2024-38356

больше 1 года назад

TinyMCE is an open source rich text editor. A cross-site scripting (XS ...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-9hcv-j9pv-qmph

больше 1 года назад

TinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp option

CVSS3: 6.1
EPSS: Низкий
fstec логотип

BDU:2024-05570

больше 1 года назад

Уязвимость редактора форматированного текста TinyMCE, существующая из-за непринятия мер по защите структуры веб-страницы, позволяющая нарушителю проводить межсайтовые сценарные атаки

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-38356

TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content extraction code. When using the `noneditable_regexp` option, specially crafted HTML attributes containing malicious code were able to be executed when content was extracted from the editor. This vulnerability has been patched in TinyMCE 7.2.0, TinyMCE 6.8.4 and TinyMCE 5.11.0 LTS by ensuring that, when using the `noneditable_regexp` option, any content within an attribute is properly verified to match the configured regular expression before being added. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 6.1
1%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-38356

TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content extraction code. When using the `noneditable_regexp` option, specially crafted HTML attributes containing malicious code were able to be executed when content was extracted from the editor. This vulnerability has been patched in TinyMCE 7.2.0, TinyMCE 6.8.4 and TinyMCE 5.11.0 LTS by ensuring that, when using the `noneditable_regexp` option, any content within an attribute is properly verified to match the configured regular expression before being added. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 6.1
1%
Низкий
больше 1 года назад
debian логотип
CVE-2024-38356

TinyMCE is an open source rich text editor. A cross-site scripting (XS ...

CVSS3: 6.1
1%
Низкий
больше 1 года назад
github логотип
GHSA-9hcv-j9pv-qmph

TinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp option

CVSS3: 6.1
1%
Низкий
больше 1 года назад
fstec логотип
BDU:2024-05570

Уязвимость редактора форматированного текста TinyMCE, существующая из-за непринятия мер по защите структуры веб-страницы, позволяющая нарушителю проводить межсайтовые сценарные атаки

CVSS3: 6.1
1%
Низкий
больше 1 года назад

Уязвимостей на страницу