Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-wqm8-jx8r-8rcq: Cross-site scripting vulnerabilities in old version of bundled TinyMCE

An old version of TinyMCE include an XSS vulnerability, which was patched in a later version. This was described by TinyMCE:

A cross-site scripting (XSS) vulnerability was discovered in the core parser. The vulnerability allowed arbitrary JavaScript execution when inserting a specially crafted piece of content into the editor via the clipboard or APIs. This impacts all users who are using TinyMCE 4.9.10 or lower and TinyMCE 5.4.0 or lower.

We reviewed the potential impact of this vulnerability within the context of Silverstripe CMS. We concluded this is a medium impact vulnerability given how TinyMCE is used by Silverstripe CMS.

Reported by: Developers at ACC

ghsa
#xss#vulnerability#git#java

Package

composer silverstripe/admin (Composer)

Affected versions

< 1.12.7

Patched versions

1.12.7

Description

An old version of TinyMCE include an XSS vulnerability, which was patched in a later version. This was described by TinyMCE:

A cross-site scripting (XSS) vulnerability was discovered in the core parser. The vulnerability allowed arbitrary JavaScript execution when inserting a specially crafted piece of content into the editor via the clipboard or APIs. This impacts all users who are using TinyMCE 4.9.10 or lower and TinyMCE 5.4.0 or lower.

We reviewed the potential impact of this vulnerability within the context of Silverstripe CMS. We concluded this is a medium impact vulnerability given how TinyMCE is used by Silverstripe CMS.

Reported by: Developers at ACC

References

  • GHSA-wqm8-jx8r-8rcq
  • GHSA-vrv8-v4w8-f95h
  • https://www.silverstripe.org/download/security-releases/ss-2023-001
  • https://www.tiny.cloud/docs/release-notes/release-notes54/#securityfixes

GuySartorelli published to silverstripe/silverstripe-admin

Apr 26, 2023

Published to the GitHub Advisory Database

Apr 26, 2023

Reviewed

Apr 26, 2023

Last updated

Apr 26, 2023

ghsa: Latest News

GHSA-237r-r8m4-4q88: Guzzle OAuth Subscriber has insufficient nonce entropy