CVE-2019-1010091: XSS
Published Jul 17, 2019
·Updated
tinymce 4.7.11, 4.7.12 is affected by: CWE-79: Improper Neutralization of Input During Web Page Generation. The impact is: JavaScript code execution. The component is: Media element. The attack vector is: The victim must paste malicious content to media element's embed tab.
Affected Software
2 affected components
Tiny TinyMCE<4.9.10
Tiny TinyMCE>=5.0.0<5.2.2
Event History
Jul 17, 2019
CVE Published
via MITRE·04:35 PM
Data Sourced
via MITRE·04:35 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2019-1010091?
CVE-2019-1010091 is a vulnerability in tinymce 4.7.11 and 4.7.12 that allows JavaScript code execution through the media element's embed tab.
2
What is the impact of CVE-2019-1010091?
The impact of CVE-2019-1010091 is JavaScript code execution.
3
How does CVE-2019-1010091 affect tinymce?
CVE-2019-1010091 affects tinymce 4.7.11 and 4.7.12 through the media element's embed tab.
4
What is the severity of CVE-2019-1010091?
The severity of CVE-2019-1010091 is medium with a CVSS score of 6.1.
5
How can I fix CVE-2019-1010091?
To fix CVE-2019-1010091, update tinymce to a version between 4.7.13 and 5.0.0 or above 5.2.2.