Moderate severityNVD Advisory· Published Jul 17, 2019· Updated Aug 5, 2024
CVE-2019-1010091
CVE-2019-1010091
Description
tinymce 4.7.11, 4.7.12 is affected by: CWE-79: Improper Neutralization of Input During Web Page Generation. The impact is: JavaScript code execution. The component is: Media element. The attack vector is: The victim must paste malicious content to media element's embed tab.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
tinymcenpm | < 4.9.10 | 4.9.10 |
tinymcenpm | >= 5.0.0, < 5.2.2 | 5.2.2 |
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/advisories/GHSA-c78w-2gw7-gjv3ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-1010091ghsaADVISORY
- github.com/tinymce/tinymce/issues/4394ghsax_refsource_MISCWEB
- github.com/tinymce/tinymce/security/advisories/GHSA-c78w-2gw7-gjv3ghsaWEB
News mentions
0No linked articles in our index yet.