First published: Wed Jan 06 2021(Updated: )
### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-5h9g-x5rv-25wg. This link is maintained to preserve external references. ### Original Description TinyMCE versions before 5.6.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting in arbitrary JavaScript execution in another user's browser.
Credit: disclosure@vulncheck.com disclosure@vulncheck.com
Affected Software | Affected Version | How to fix |
---|---|---|
npm/tinymce | <5.6.0 | |
composer/tinymce/tinymce | <5.6.0 | 5.6.0 |
nuget/TinyMCE | <5.6.0 | 5.6.0 |
npm/tinymce | <5.6.0 | 5.6.0 |
TinyMCE | <5.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-21911 is classified as a stored cross-site scripting vulnerability affecting TinyMCE versions before 5.6.0.
To mitigate CVE-2024-21911, upgrade TinyMCE to version 5.6.0 or later.
CVE-2024-21911 affects TinyMCE versions prior to 5.6.0.
CVE-2024-21911 is a stored cross-site scripting (XSS) vulnerability.
Detailed information about CVE-2024-21911 can be found in the original advisory related to it.