SCA: security update for TinyMCE, tinymce, tinymce/tinymce (GHSA-gg8r-xjwq-4w92)

medium Tenable Cloud Security Plugin ID 415109

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- tinymce is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in
the alert and confirm dialogs when these dialogs were provided with malicious HTML content. This can occur
in plugins that use the alert or confirm dialogs, such as in the `image` plugin, which presents these
dialogs when certain errors occur. The vulnerability allowed arbitrary JavaScript execution when an alert
presented in the TinyMCE UI for the current user. This vulnerability has been patched in TinyMCE 5.10.7
and TinyMCE 6.3.1 by ensuring HTML sanitization was still performed after unwrapping invalid elements.
Users are advised to upgrade to either 5.10.7 or 6.3.1. Users unable to upgrade may ensure the the
`images_upload_handler` returns a valid value as per the images_upload_handler documentation.
(CVE-2022-23494)

See Also

https://github.com/advisories/GHSA-gg8r-xjwq-4w92

Plugin Details

Severity: Medium

ID: 415109

Version: Revision 1.7

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 2.3

Percentile: 9.36

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Temporal Score: 4.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS Score Source: CVE-2022-23494

CVSS v3

Risk Factor: Medium

Base Score: 6.1

Temporal Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 12/8/2022

Vulnerability Publication Date: 12/8/2022

Reference Information

CVE: CVE-2022-23494

cwe: CWE-79