Description
A cross-site scripting (XSS) vulnerability in TinyMCE 5.2.1 and earlier allows remote attackers to inject arbitrary web script when configured in classic editing mode.
Remediation
References
https://labs.bishopfox.com/advisories/tinymce-version-5.2.1
Related Vulnerabilities
CVE-2023-50164 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2021-32859 Vulnerability in npm package baremetrics-calendar
CVE-2019-12400 Vulnerability in maven package org.apache.santuario:xmlsec
CVE-2021-27516 Vulnerability in maven package org.webjars.npm:urijs
CVE-2016-10680 Vulnerability in npm package adamvr-geoip-lite