CVE-2024-21910
TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attack
TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attacker could introduce crafted image or link URLs that would result in the execution of arbitrary JavaScript in an editing user's browser.
MEDIUM · CVSS 6.1
EPSS 0.04084
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0