TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content parsing code. This allowed specially crafted noscript elements containing malicious code to be executed when that content was loaded into the editor. This vulnerability has been patched in TinyMCE 7.2.0, TinyMCE 6.8.4 and TinyMCE 5.11.0 LTS by ensuring that content within noscript elements are properly parsed. Users are advised to upgrade. There are no known workarounds for this vulnerability.
                
            Metrics
Affected Vendors & Products
References
        History
                    No history.
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-06-19T20:03:49.806Z
Updated: 2024-08-02T04:04:25.258Z
Reserved: 2024-06-14T14:16:16.464Z
Link: CVE-2024-38357
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-06-20T13:07:59.295Z
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2024-06-19T20:15:11.727
Modified: 2024-11-21T09:25:26.463
Link: CVE-2024-38357
 Redhat
                        Redhat
                    No data.