Логотип exploitDog
bind:CVE-2024-38357
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-38357

Количество 5

Количество 5

ubuntu логотип

CVE-2024-38357

больше 1 года назад

TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content parsing code. This allowed specially crafted noscript elements containing malicious code to be executed when that content was loaded into the editor. This vulnerability has been patched in TinyMCE 7.2.0, TinyMCE 6.8.4 and TinyMCE 5.11.0 LTS by ensuring that content within noscript elements are properly parsed. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2024-38357

больше 1 года назад

TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content parsing code. This allowed specially crafted noscript elements containing malicious code to be executed when that content was loaded into the editor. This vulnerability has been patched in TinyMCE 7.2.0, TinyMCE 6.8.4 and TinyMCE 5.11.0 LTS by ensuring that content within noscript elements are properly parsed. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2024-38357

больше 1 года назад

TinyMCE is an open source rich text editor. A cross-site scripting (XS ...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-w9jx-4g6g-rp7x

больше 1 года назад

TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements

CVSS3: 6.1
EPSS: Низкий
fstec логотип

BDU:2024-08354

больше 1 года назад

Уязвимость редактора форматированного текста TinyMCE, существующая из-за непринятия мер по защите структуры веб-страницы, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-38357

TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content parsing code. This allowed specially crafted noscript elements containing malicious code to be executed when that content was loaded into the editor. This vulnerability has been patched in TinyMCE 7.2.0, TinyMCE 6.8.4 and TinyMCE 5.11.0 LTS by ensuring that content within noscript elements are properly parsed. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 6.1
1%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-38357

TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content parsing code. This allowed specially crafted noscript elements containing malicious code to be executed when that content was loaded into the editor. This vulnerability has been patched in TinyMCE 7.2.0, TinyMCE 6.8.4 and TinyMCE 5.11.0 LTS by ensuring that content within noscript elements are properly parsed. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 6.1
1%
Низкий
больше 1 года назад
debian логотип
CVE-2024-38357

TinyMCE is an open source rich text editor. A cross-site scripting (XS ...

CVSS3: 6.1
1%
Низкий
больше 1 года назад
github логотип
GHSA-w9jx-4g6g-rp7x

TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements

CVSS3: 6.1
1%
Низкий
больше 1 года назад
fstec логотип
BDU:2024-08354

Уязвимость редактора форматированного текста TinyMCE, существующая из-за непринятия мер по защите структуры веб-страницы, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

CVSS3: 6.1
1%
Низкий
больше 1 года назад

Уязвимостей на страницу