QID 982988
QID 982988: Nodejs (npm) Security Update for tinymce (GHSA-c78w-2gw7-gjv3)
Security update has been released for tinymce to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
A cross-site scripting (XSS) vulnerability was discovered in: the core parser and `media` plugin. The vulnerability allowed arbitrary JavaScript execution when inserting a specially crafted piece of content into the editor via the clipboard or APIs. This impacts all users who are using TinyMCE 4.9.9 or lower and TinyMCE 5.2.1 or lower.
Solution
This vulnerability has been patched in TinyMCE 4.9.10 and 5.2.2 by improved HTML parsing and sanitization logic.Workaround:
The workarounds available are:
- disable the media plugin and manually sanitize CDATA content (see below)
or
- upgrade to either TinyMCE 4.9.10 or TinyMCE 5.2.2
The workarounds available are:
- disable the media plugin and manually sanitize CDATA content (see below)
or
- upgrade to either TinyMCE 4.9.10 or TinyMCE 5.2.2
Vendor References
- GHSA-c78w-2gw7-gjv3 -
github.com/advisories/GHSA-c78w-2gw7-gjv3
CVEs related to QID 982988
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-c78w-2gw7-gjv3 | tinymce |
|