Advertisement






iframeHTML Injection TinyMCE 5 HTML WYSIWYG

CVE Category Price Severity
N/A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') N/A High
Author Risk Exploitation Type Date
Unknown Critical Remote 2020-10-18
CVSS EPSS EPSSP
Not specified 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2020100106

Below is a copy:

iframeHTML Injection TinyMCE 5 HTML WYSIWYG
# Exploit Title: iframe\HTML Injection TinyMCE 5 HTML WYSIWYG 
# Date:18.10.2020
# Author: Vincent666 ibn Winnie
# Software Link: https://www.tiny.cloud/features/
# Tested on: Windows 10
# Web Browser: Mozilla Firefox
# Blog : https://pentest-vincent.blogspot.com/
# PoC: https://pentest-vincent.blogspot.com/2020/10/iframehtml-injection-tinymce-5-html.html

PoC:

We have iframe injection in TinyMCE 5. 

I use for example demo TinyMCE and Plone Cms with TinyMCE. 

Our iframe injection on the demo:

Insert - Media - Embed - our iframe code. 

In the demo Plone Cms:

Insert - Image - Caption - our iframe code. 

If a simple user can inject his code into these fields, then he can use it.

What can you do with Iframe Injection?

Different things. More often this is phishing attack.
 
With Html Injection you can change background and change something what you want.  

Picture:

https://imgur.com/a/IM6PBQh

Iframe injection video:

https://www.youtube.com/watch?v=KHbhD_zmWcI&feature=youtu.be

Html injection video :

https://www.youtube.com/watch?v=IoR89uQcbGc&feature=youtu.be




Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum