A cross-site scripting (XSS) vulnerability in TinyMCE 5.2.1 and earlier allows remote attackers to inject arbitrary web script when configured in classic editing mode. Reference: https://labs.bishopfox.com/advisories/tinymce-version-5.2.1
Created tinymce tracking bugs for this issue: Affects: epel-6 [bug 1868974] Affects: fedora-all [bug 1868973]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.