Description
A cross-site scripting (XSS) vulnerability in TinyMCE 5.2.1 and earlier allows remote attackers to inject arbitrary web script when configured in classic editing mode.
Remediation
References
Related Vulnerabilities
TYPO3 Insertion of Sensitive Information into Log File Vulnerability (CVE-2021-32767)
WordPress Plugin Form for WordPress-Zoho Forms Cross-Site Scripting (3.0)
TYPO3 Deserialization of Untrusted Data Vulnerability (CVE-2019-12747)
MediaWiki Exposure of Resource to Wrong Sphere Vulnerability (CVE-2021-31554)
WordPress Plugin Tutor LMS-eLearning and online course solution Security Bypass (2.6.1)