First published: Tue Nov 02 2021(Updated: )
### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-5h9g-x5rv-25wg. This link is maintained to preserve external references. ### Original Description TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attacker could introduce crafted image or link URLs that would result in the execution of arbitrary JavaScript in an editing user's browser.
Credit: disclosure@vulncheck.com disclosure@vulncheck.com
Affected Software | Affected Version | How to fix |
---|---|---|
pip/django-tinymce | <3.4.0 | 3.4.0 |
nuget/TinyMCE | <5.10.0 | 5.10.0 |
composer/tinymce/tinymce | <5.10.0 | 5.10.0 |
npm/tinymce | <5.10.0 | 5.10.0 |
npm/tinymce | <5.10.0 | |
TinyMCE | <5.10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-21910 is classified as a cross-site scripting vulnerability affecting TinyMCE versions prior to 5.10.0.
To mitigate CVE-2024-21910, upgrade TinyMCE to version 5.10.0 or later.
TinyMCE versions before 5.10.0 are affected by CVE-2024-21910.
Yes, CVE-2024-21910 can be exploited remotely through a cross-site scripting attack.
Yes, the patch for CVE-2024-21910 is included in TinyMCE version 5.10.0 and later.