CVE-2023-45818 is a mutation cross-site scripting (mXSS) vulnerability affecting TinyMCE 5 and 6, specifically within its undo/redo functionality. A carefully crafted HTML snippet, after passing sanitization, can be maliciously mutated upon restoration from the undo stack due to string manipulation and reparative parsing, leading to XSS execution. This vulnerability has a CVSS score of 6.1 (Medium), indicating a network-based attack requiring user interaction, with potential for low impact on confidentiality and integrity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.10.8CPE matchmatch criteria | cpe:2.3:a:tiny:tinymce:*:*:*:*:*:*:*:* | ||
>= 6.0.0, < 6.7.1CPE matchmatch criteria | cpe:2.3:a:tiny:tinymce:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.