CVE Published: 03/01/2024 |
CVE Updated: 01/08/2024 |
CVE Year: 2024 Source: VulnCheck |
Vendor: |
Product: Status : PUBLISHED
CVE-2024-21908 Description
TinyMCE versions before 5.9.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting in arbitrary JavaScript execution in another user\'s browser.