First published: Mon Jun 26 2023(Updated: )
Cross Site Scripting vulnerability in TinyMCE v.4.9.6 and before and v.5.0.0 thru v.5.1.4 allows an attacker to execute arbitrary code via the editor function.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TinyMCE | <=4.9.6 | |
TinyMCE | >=5.0.0<=5.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-23066.
The severity of CVE-2020-23066 is medium (CVSS score: 6.1).
The affected software is TinyMCE versions 4.9.6 and earlier, and versions 5.0.0 through 5.1.4.
An attacker can exploit CVE-2020-23066 by executing arbitrary code via the editor function.
To fix CVE-2020-23066, update TinyMCE to version 5.1.5 or higher.