What the vulnerability does
01Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tim Reeves & David Stöckl TinyMCE Custom Styles plugin <= 1.1.2 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tim Reeves & David Stöckl TinyMCE Custom Styles plugin <= 1.1.2 versions.
Explanation of Vulnerability in Simple Terms
TinyMCE Custom Styles versions up to 1.1.2 contain a cross-site scripting (XSS) vulnerability in how custom styles are processed. An authenticated user with high privileges can inject malicious scripts that execute in the browser of another user who views the affected content. The vulnerability requires user interaction and can affect the confidentiality, integrity, and availability of the site.
What an attacker can do
Inject malicious scripts that run in other users' browsers when they view custom styles.
Potential impact on your site
Authenticated admins can inject scripts affecting other users' sessions, potentially compromising accounts or site data.
Conditions required to exploit
Attacker must have high-level admin privileges and the victim must view a page containing the malicious custom style.
Key dates
External resources
Related vulnerabilities