GHSA-wqm8-jx8r-8rcq

    Dashboard / Vulnerabilities / GHSA-wqm8-jx8r-8rcq

    GHSA-wqm8-jx8r-8rcq

    Published: 26 Apr 2023Last Modified: 4 Dec 2024

    Summary: Cross-site scripting vulnerabilities in old version of bundled TinyMCE

    Details: An old version of TinyMCE include an XSS vulnerability, which was patched in a later version. This was described by TinyMCE: > A cross-site scripting (XSS) vulnerability was discovered in the core parser. The vulnerability allowed arbitrary JavaScript execution when inserting a specially crafted piece of content into the editor via the clipboard or APIs. This impacts all users who are using TinyMCE 4.9.10 or lower and TinyMCE 5.4.0 or lower. We reviewed the potential impact of this vulnerability within the context of Silverstripe CMS. We concluded this is a medium impact vulnerability given how TinyMCE is used by Silverstripe CMS. Reported by: Developers at ACC

    Affected packages

    Package

    Name: silverstripe/admin

    Purl: pkg:composer/silverstripe/admin

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.12.7

    Affected versions

    1.0.0
    1.0.0-alpha6
    1.0.0-alpha7
    1.0.0-beta1
    1.0.0-beta2
    1.0.0-beta3
    1.0.0-beta4
    1.0.0-rc1
    1.0.0-rc2
    1.0.0-rc3
    1.0.1
    1.0.1-rc1
    1.0.2
    1.0.3
    1.0.4
    1.0.5
    1.0.6
    1.0.7

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-wqm8-jx8r-8rcq | CVE-DB