TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by using the clipboard or APIs to insert content into the editor.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-08-10T19:34:35

Updated: 2020-08-10T19:34:35

Reserved: 2020-08-10T00:00:00


Link: CVE-2020-17480

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-08-10T20:15:11.737

Modified: 2020-08-11T15:47:37.900


Link: CVE-2020-17480

JSON object: View

cve-icon Redhat Information

No data.

CWE