CVE-2020-17480
Summary
| CVE | CVE-2020-17480 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-08-10 20:15:00 UTC |
| Updated | 2020-08-11 15:47:00 UTC |
| Description | TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by using the clipboard or APIs to insert content into the editor. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| TinyMCE | TinyMCE 5.1.4 | MISC | www.tiny.cloud | Release Notes, Vendor Advisory |
| Cross-site scripting vulnerability in TinyMCE · Advisory · tinymce/tinymce · GitHub | MISC | github.com | Exploit, Release Notes, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 982665 Nodejs (npm) Security Update for tinymce (GHSA-p7j5-4mwm-hv86)