VulnerabilityModified
CVE-2020-17480
TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by using the clipboard or APIs to insert content into the editor.
MEDIUM 6.1EPSS 1.25%
Does this matter?
Lower severity and a low EPSS score (1.25%). Track it; it rarely justifies an emergency change on its own.
Description
TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by using the clipboard or APIs to insert content into the editor.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.25% probability · 68th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- tiny/tinymce
- Source
- cve@mitre.org
References
- https://github.com/tinymce/tinymce/security/advisories/GHSA-27gm-ghr9-4v95Exploit, Release Notes, Third Party Advisory
- https://www.tiny.cloud/docs/release-notes/release-notes514/#securityfixesRelease Notes, Vendor Advisory
- https://github.com/tinymce/tinymce/security/advisories/GHSA-27gm-ghr9-4v95Exploit, Release Notes, Third Party Advisory
- https://www.tiny.cloud/docs/release-notes/release-notes514/#securityfixesRelease Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.