Description
A cross-site scripting (XSS) vulnerability in TinyMCE 5.2.1 and earlier allows remote attackers to inject arbitrary web script when configured in classic editing mode.
Remediation
References
https://labs.bishopfox.com/advisories/tinymce-version-5.2.1
Related Vulnerabilities
CVE-2020-6454 Vulnerability in maven package org.webjars.npm:electron
CVE-2017-16132 Vulnerability in npm package simple-npm-registry
CVE-2014-3623 Vulnerability in maven package org.apache.cxf:cxf-rt-security
CVE-2020-19697 Vulnerability in maven package org.webjars.bowergithub.pandao:editor.md
CVE-2020-7663 Vulnerability in maven package org.webjars.npm:websocket-extensions