QID 982665
QID 982665: Nodejs (npm) Security Update for tinymce (GHSA-p7j5-4mwm-hv86)
TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by using the clipboard or APIs to insert content into the editor.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-p7j5-4mwm-hv86 for updates pertaining to this vulnerability.
Vendor References
- GHSA-p7j5-4mwm-hv86 -
github.com/advisories/GHSA-p7j5-4mwm-hv86
CVEs related to QID 982665
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-p7j5-4mwm-hv86 | tinymce |
|