TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by using the clipboard or APIs to insert content into the editor.
References
Link | Resource |
---|---|
https://github.com/tinymce/tinymce/security/advisories/GHSA-27gm-ghr9-4v95 | Exploit Release Notes Third Party Advisory |
https://www.tiny.cloud/docs/release-notes/release-notes514/#securityfixes | Release Notes Vendor Advisory |
https://github.com/tinymce/tinymce/security/advisories/GHSA-27gm-ghr9-4v95 | Exploit Release Notes Third Party Advisory |
https://www.tiny.cloud/docs/release-notes/release-notes514/#securityfixes | Release Notes Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 05:08
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/tinymce/tinymce/security/advisories/GHSA-27gm-ghr9-4v95 - Exploit, Release Notes, Third Party Advisory | |
References | () https://www.tiny.cloud/docs/release-notes/release-notes514/#securityfixes - Release Notes, Vendor Advisory |
Information
Published : 2020-08-10 20:15
Updated : 2024-11-21 05:08
NVD link : CVE-2020-17480
Mitre link : CVE-2020-17480
CVE.ORG link : CVE-2020-17480
JSON object : View
Products Affected
tiny
- tinymce
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')