Pimcore TinyMCE Bundle - tinymce CVE-2024-29203, CVE-2024-29881
Package
Affected versions
>= 11.2.0, < 11.2.3
>= 11.0.0-ALPHA1, < 11.1.6.5
Patched versions
11.2.3
11.1.6.5
Description
Published to the GitHub Advisory Database
Apr 24, 2024
Reviewed
Apr 24, 2024
Last updated
May 8, 2024
Impact
The TineMCE Bundle uses tinymce version 6.7.3. CVEs for this version exists for <6.8.1:
https://nvd.nist.gov/vuln/detail/CVE-2024-29203
https://nvd.nist.gov/vuln/detail/CVE-2024-29881
Patches
The package should be updated to at least 6.8.1 to avoid XSS vulnerability.
Workarounds
Upgrade pimcore to release 11.2.3 or 11.1.6.5.
References
https://nvd.nist.gov/vuln/detail/CVE-2024-29203
https://nvd.nist.gov/vuln/detail/CVE-2024-29881
References