Critical TinyMCE Cross Site Scripting Flaws Threaten Millions of Applications
ID: 36cca833-9342-5d81-87a0-970b4f97fd27
STIX ID: report--36cca833-9342-5d81-87a0-970b4f97fd27
Feed Name: securityonline.info
Threat Score
A security advisory details multiple critical cross-site scripting and sanitization vulnerabilities in the TinyMCE rich text editor that allow remote attackers to inject and execute malicious scripts via crafted media plugin attributes, improper namespace handling in the sanitizer, prefixed source/link attributes, and forged document comments; the flaws affect widely deployed versions and require immediate patching (upgrade to 7.9.3+, 8.5.1 or obtain LTS fixes).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
