CVE-2024-21910: Cross-site scripting vulnerability in TinyMCE plugins

Published Nov 2, 2021
·
Updated

Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-5h9g-x5rv-25wg. This link is maintained to preserve external references.

Original Description TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attacker could introduce crafted image or link URLs that would result in the execution of arbitrary JavaScript in an editing user's browser.

Other sources

Impact A cross-site scripting (XSS) vulnerability was discovered in the URL processing logic of the image and link plugins. The vulnerability allowed arbitrary JavaScript execution when updating an image or link using a specially crafted URL. This issue only impacted users while editing and the dangerous URLs were stripped in any content extracted from the editor. This impacts all users who are using TinyMCE 5.9.2 or lower.

Patches This vulnerability has been patched in TinyMCE 5.10.0 by improved sanitization logic when updating URLs in the relevant plugins.

Workarounds To work around this vulnerability, either: - Upgrade to TinyMCE 5.10.0 or higher - Disable the image and link plugins

Acknowledgements Tiny Technologies would like to thank Yakir6 for discovering this vulnerability.

References https://www.tiny.cloud/docs/release-notes/release-notes510/#securityfixes

For more information If you have any questions or comments about this advisory: Email us at infosec@tiny.cloud Open an issue in the TinyMCE repo

Affected Software

6 affected componentsFixes available
pip/django-tinymce<3.4.0
3.4.0
nuget/TinyMCE<5.10.0
5.10.0
composer/tinymce/tinymce<5.10.0
5.10.0
npm/tinymce<5.10.0
5.10.0
npm/tinymce<5.10.0
Tiny TinyMCE<5.10.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/django-tinymce to a version that resolves this vulnerability.

    Fixed in 3.4.0
  2. Upgrade

    Upgrade nuget/TinyMCE to a version that resolves this vulnerability.

    Fixed in 5.10.0
  3. Upgrade

    Upgrade composer/tinymce/tinymce to a version that resolves this vulnerability.

    Fixed in 5.10.0
  4. Upgrade

    Upgrade npm/tinymce to a version that resolves this vulnerability.

    Fixed in 5.10.0
  5. Upgrade

    Upgrade TinyMCE to a version that resolves this vulnerability.

    Fixed in 5.10.0
  6. Configuration

    Disable the `image` and `link` plugins in TinyMCE to mitigate the XSS issue in the URL processing logic.

    TinyMCE plugins.image and plugins.link = disabled

Event History

Nov 2, 2021
Advisory Published
03:42 PM
Jan 3, 2024
CVE Published
03:55 PM
Data Sourced
03:55 PM
DescriptionWeakness

Frequently Asked Questions

1

What is the severity of CVE-2024-21910?

CVE-2024-21910 is classified as a cross-site scripting vulnerability affecting TinyMCE versions prior to 5.10.0.

2

How do I fix CVE-2024-21910?

To mitigate CVE-2024-21910, upgrade TinyMCE to version 5.10.0 or later.

3

Which versions of TinyMCE are affected by CVE-2024-21910?

TinyMCE versions before 5.10.0 are affected by CVE-2024-21910.

4

Can CVE-2024-21910 be exploited remotely?

Yes, CVE-2024-21910 can be exploited remotely through a cross-site scripting attack.

5

Is there a patch for CVE-2024-21910 available?

Yes, the patch for CVE-2024-21910 is included in TinyMCE version 5.10.0 and later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203