Junglewise Threat Intelligence

CVE-2023-45818: TinyMCE mutation XSS in undo/redo and content APIs

CVE-2023-45818 · Severity: low · CVSS 3.1 · Published 2023-10-19

Technologies: Tiny Technologies Tinymce.

Executive brief

TinyMCE is a widely-used rich text editor embedded in web applications. A mutation cross-site scripting (mXSS) vulnerability allows attackers to bypass the editor's HTML sanitization through manipulation of undo/redo operations and related APIs. By restoring carefully-crafted HTML from the undo stack, malicious JavaScript can be executed in the context of the user's browser, potentially compromising data and sessions.

Technical details

This mXSS vulnerability exists in TinyMCE's undo/redo functionality, getContent API (raw format), resetContent API, and Autosave plugin. The root cause is the use of string-level HTML trimming before storing content in the undo stack. When content is restored, browser parsing (via DOMParser in TinyMCE 6 or SaxParser in TinyMCE 5) mutates the carefully-crafted HTML snippet, transforming sanitized markup into executable XSS payload. Attack requires user interaction (triggering undo/redo or using affected APIs) and network-accessible TinyMCE instance, but no authentication. The vulnerability has been patched in TinyMCE 5.10.8 and 6.7.1 by switching to node-level HTML manipulation instead of string manipulation.

Affected products

  • Tiny Technologies TinyMCE all versions before 5.10.8 and 6.0.0–6.7.0

Timeline

  • 2023-10-19: disclosed
  • 2023-10-19: patched: TinyMCE 5.10.8 and 6.7.1 released with fix

References