CVE-2020-17480: XSS
Published Aug 10, 2020
·Updated
TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by using the clipboard or APIs to insert content into the editor.
Affected Software
2 affected components
Tiny TinyMCE<4.9.7
Tiny TinyMCE>=5.0.0<5.1.4
Event History
Aug 10, 2020
CVE Published
via MITRE·07:34 PM
Data Sourced
via MITRE·07:34 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2020-17480.
2
What is the severity level of CVE-2020-17480?
The severity level of CVE-2020-17480 is medium (6.1).
3
Which software versions are affected by CVE-2020-17480?
TinyMCE versions before 4.9.7 and 5.x before 5.1.4 are affected by CVE-2020-17480.
4
What is the CWE category of CVE-2020-17480?
The CWE category of CVE-2020-17480 is CWE-79 (Cross-Site Scripting).
5
How can the XSS vulnerability be exploited in TinyMCE?
The XSS vulnerability in TinyMCE can be exploited by using the clipboard or APIs to insert content into the editor.