CVE-2024-38357

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Jun 19, 2024
Updated: Jun 20, 2024
CWE ID 79

Summary

CVE-2024-38357 is a newly discovered cross-site scripting (XSS) vulnerability affecting the open-source rich text editor, TinyMCE. The issue lies within TinyMCE's content parsing code, which inadequately handles noscript elements. Malicious code within specifically crafted noscript tags can be executed when loading such content into the editor. Users are urged to upgrade to TinyMCE 7.2.0, 6.8.4, or 5.11.0 LTS to apply the necessary patches and prevent exploitation. There are currently no known workarounds for this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share