Junglewise Threat Intelligence

CVE-2024-29203: TinyMCE cross-site scripting in iframe handling

CVE-2024-29203 · Severity: low · CVSS 3.1 · Published 2024-03-26

Technologies: Tinymce. Vendors: npm.

Executive brief

TinyMCE is a JavaScript rich-text editor used in content management systems and web applications. A cross-site scripting (XSS) vulnerability in iframe handling allowed attackers to inject malicious code into editors, potentially leading to data theft, credential harvesting, or malware distribution to end users viewing the compromised content.

Technical details

A cross-site scripting (XSS) vulnerability exists in TinyMCE's content insertion code that fails to properly sanitize iframe elements containing malicious scripts. When an attacker inserts an iframe with embedded JavaScript into the editor, the code executes within the editor's context. Although iframe permissions are partially restricted by browser same-origin policy, execution can still trigger dangerous operations such as downloading malicious assets, exfiltrating clipboard data, or accessing DOM content. The vulnerability requires user interaction (inserting content into the editor). The fix introduces a sandbox_iframes boolean option (enabled by default in TinyMCE 7.0.0) that adds the sandbox="" attribute to all iframe elements, preventing cross-origin and same-origin XSS. TinyMCE 7.0.0 also introduced sandbox_iframes_exclusions to allow selective exclusion of trusted domains from sandboxing.

Affected products

  • TinyMCE TinyMCE <6.8.1 (npm), <7.0.0 (complete fix with default enabled)
  • TinyMCE TinyMCE (NuGet) <7.0.0
  • TinyMCE TinyMCE (Composer) <7.0.0

Timeline

  • 2024-03-26: disclosed: Vulnerability advisory GHSA-438c-3975-5x3f published
  • 2023-11-21: patched: Fix committed as part of TinyMCE 6.8.1 with sandbox_iframes option (disabled by default)
  • 2024: patched: TinyMCE 7.0.0 released with sandbox_iframes enabled by default

References

Related threats