原始 OSV JSON{
"id": "GHSA-p7j5-4mwm-hv86",
"aliases": [],
"details": "## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-27gm-ghr9-4v95. This link is maintained to preserve external references.\n\n## Original Description\nTinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by using the clipboard or APIs to insert content into the editor.",
"summary": "Duplicate Advisory: Cross-site scripting in TinyMCE",
"affected": [
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "4.9.7"
}
]
}
],
"package": {
"name": "tinymce",
"ecosystem": "npm"
}
},
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "5.0.0"
},
{
"fixed": "5.1.4"
}
]
}
],
"package": {
"name": "tinymce",
"ecosystem": "npm"
}
}
],
"modified": "2023-06-27T16:50:42Z",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"published": "2021-05-06T17:28:14Z",
"withdrawn": "2023-06-27T16:40:59Z",
"references": [
{
"url": "https://github.com/tinymce/tinymce/security/advisories/GHSA-27gm-ghr9-4v95",
"type": "WEB"
},
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-17480",
"type": "ADVISORY"
},
{
"url": "https://www.tiny.cloud/docs/release-notes/release-notes514/#securityfixes",
"type": "WEB"
}
],
"schema_version": "1.4.0",
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": true,
"nvd_published_at": "2020-08-10T20:15:00Z",
"github_reviewed_at": "2021-05-05T22:23:10Z"
}
}