First published: Fri Aug 14 2020(Updated: )
A cross-site scripting (XSS) vulnerability in TinyMCE 5.2.1 and earlier allows remote attackers to inject arbitrary web script when configured in classic editing mode.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tiny TinyMCE | <4.9.11 | |
Tiny TinyMCE | >=5.0.0<5.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12648 is a cross-site scripting (XSS) vulnerability in TinyMCE 5.2.1 and earlier versions.
The severity of CVE-2020-12648 is medium with a CVSS score of 6.1.
CVE-2020-12648 allows remote attackers to inject arbitrary web script when configured in classic editing mode.
TinyMCE versions 4.9.11 to 5.2.1 are affected by CVE-2020-12648.
Yes, upgrade to TinyMCE version 5.4.1 or later to fix CVE-2020-12648.