CVE-2023-45819

Not long ago, I discovered a cross-site scripting vulnerability affecting versions < 6.4.2 and <5.10.81 of TinyMCE. Initially, I thought it was just a recreation of CVE-2022-23494. However, after further research, I concluded that it was a similar but separate issue (now classified as CVE-2023-45819). TinyMCE TinyMCE is a popular open-source WYSIWYG (What You See Is What You Get) rich-text editor used by more than 1.5 million developers2. It provides a user-friendly interface for creating and editing rich-text content on websites and web applications....

October 22, 2023 · 3 min · 517 words · Philip Sinnott