CVE-2024-21910

NameCVE-2024-21910
DescriptionTinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attacker could introduce crafted image or link URLs that would result in the execution of arbitrary JavaScript in an editing user's browser.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
tinymce (PTS)jessie, stretch3.4.8+dfsg0-1vulnerable
buster3.4.8+dfsg0-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
tinymcesourcejessie(unfixed)end-of-life
tinymcesourcestretch(unfixed)end-of-life
tinymcesourcebuster(unfixed)end-of-life
tinymcesource(unstable)(unfixed)

Notes

https://github.com/tinymce/tinymce/security/advisories/GHSA-r8hm-w5f7-wj39

Search for package or bug name: Reporting problems