Skip to content

Pimcore TinyMCE Bundle - tinymce CVE-2024-29203, CVE-2024-29881

Moderate
wisconaut published GHSA-vjwg-28gv-pm8h Apr 24, 2024

Package

composer pimcore/pimcore (Composer)

Affected versions

11.x

Patched versions

11.2.3 11.1.6.5

Description

Impact

The TineMCE Bundle uses tinymce version 6.7.3. CVEs for this version exists for <6.8.1:
https://nvd.nist.gov/vuln/detail/CVE-2024-29203
https://nvd.nist.gov/vuln/detail/CVE-2024-29881

Patches

The package should be updated to at least 6.8.1 to avoid XSS vulnerability.

Workarounds

Upgrade pimcore to release 11.2.3 or 11.1.6.5.

References

https://nvd.nist.gov/vuln/detail/CVE-2024-29203
https://nvd.nist.gov/vuln/detail/CVE-2024-29881

Severity

Moderate

CVE ID

No known CVE

Weaknesses

No CWEs

Credits