Description
A cross-site scripting (XSS) vulnerability in TinyMCE 5.2.1 and earlier allows remote attackers to inject arbitrary web script when configured in classic editing mode.
Remediation
References
https://labs.bishopfox.com/advisories/tinymce-version-5.2.1
Related Vulnerabilities
CVE-2015-3250 Vulnerability in maven package org.apache.directory.api:apache-ldap-api
CVE-2020-7714 Vulnerability in npm package confucious
CVE-2019-1351 Vulnerability in maven package org.webjars.npm:nodegit
CVE-2022-48285 Vulnerability in npm package jszip
CVE-2022-24819 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates