GHSA-wqm8-jx8r-8rcq

Suggest an improvement
Source
https://github.com/advisories/GHSA-wqm8-jx8r-8rcq
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/04/GHSA-wqm8-jx8r-8rcq/GHSA-wqm8-jx8r-8rcq.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-wqm8-jx8r-8rcq
Published
2023-04-26T15:54:44Z
Modified
2024-12-04T05:40:08.202035Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Cross-site scripting vulnerabilities in old version of bundled TinyMCE
Details

An old version of TinyMCE include an XSS vulnerability, which was patched in a later version. This was described by TinyMCE:

A cross-site scripting (XSS) vulnerability was discovered in the core parser. The vulnerability allowed arbitrary JavaScript execution when inserting a specially crafted piece of content into the editor via the clipboard or APIs. This impacts all users who are using TinyMCE 4.9.10 or lower and TinyMCE 5.4.0 or lower.

We reviewed the potential impact of this vulnerability within the context of Silverstripe CMS. We concluded this is a medium impact vulnerability given how TinyMCE is used by Silverstripe CMS.

Reported by: Developers at ACC

Database specific
{
    "nvd_published_at": null,
    "cwe_ids": [],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2023-04-26T15:54:44Z"
}
References

Affected packages

Packagist / silverstripe/admin

Package

Name
silverstripe/admin
Purl
pkg:composer/silverstripe/admin

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.12.7

Affected versions

1.*

1.0.0-alpha6
1.0.0-alpha7
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0
1.0.1-rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.1.0-rc1
1.1.0-rc2
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0-beta1
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.3.0-rc1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0-rc1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.5.0-alpha1
1.5.0-rc1
1.5.0-rc2
1.5.0
1.5.1
1.5.2
1.6.0-beta1
1.6.0-rc1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0-beta1
1.7.0-rc1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0-beta1
1.8.0-rc1
1.8.0
1.8.1
1.9.0-alpha1
1.9.0-beta1
1.9.0-rc1
1.9.0
1.10.0-beta1
1.10.0-rc1
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0-beta1
1.11.0-rc1
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0-beta1
1.12.0-rc1
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6