CVE-2020-12648: XSS
Published Aug 14, 2020
·Updated
A cross-site scripting (XSS) vulnerability in TinyMCE 5.2.1 and earlier allows remote attackers to inject arbitrary web script when configured in classic editing mode.
Affected Software
2 affected components
Tiny TinyMCE<4.9.11
Tiny TinyMCE>=5.0.0<5.4.1
Event History
Aug 14, 2020
CVE Published
via MITRE·01:52 PM
Data Sourced
via MITRE·01:52 PM
Description
Frequently Asked Questions
1
What is CVE-2020-12648?
CVE-2020-12648 is a cross-site scripting (XSS) vulnerability in TinyMCE 5.2.1 and earlier versions.
2
What is the severity of CVE-2020-12648?
The severity of CVE-2020-12648 is medium with a CVSS score of 6.1.
3
How does CVE-2020-12648 affect TinyMCE?
CVE-2020-12648 allows remote attackers to inject arbitrary web script when configured in classic editing mode.
4
Which versions of TinyMCE are affected by CVE-2020-12648?
TinyMCE versions 4.9.11 to 5.2.1 are affected by CVE-2020-12648.
5
Is there a fix for CVE-2020-12648?
Yes, upgrade to TinyMCE version 5.4.1 or later to fix CVE-2020-12648.