What the vulnerability does
01Description
Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.
Explanation of Vulnerability in Simple Terms
TinyMCE Templates versions up to 4.8.1 expose sensitive information to authenticated users with low privileges. An attacker with a low-privilege account can read data they should not have access to. The vulnerability requires network access and an active login but no additional user interaction. Update to a version newer than 4.8.1.
What an attacker can do
Read sensitive data accessible through the TinyMCE Templates interface that should be restricted from their account level.
Potential impact on your site
Low-privilege users (e.g., contributors, subscribers) can view confidential information not intended for their role.
Conditions required to exploit
Attacker must have a low-privilege account on the site and network access to the application.
Key dates
External resources
Related vulnerabilities