iframeHTML Injection TinyMCE 5 HTML WYSIWYG

2020.10.18
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: N/A

# Exploit Title: iframe\HTML Injection TinyMCE 5 HTML WYSIWYG # Date:18.10.2020 # Author: Vincent666 ibn Winnie # Software Link: https://www.tiny.cloud/features/ # Tested on: Windows 10 # Web Browser: Mozilla Firefox # Blog : https://pentest-vincent.blogspot.com/ # PoC: https://pentest-vincent.blogspot.com/2020/10/iframehtml-injection-tinymce-5-html.html PoC: We have iframe injection in TinyMCE 5. I use for example demo TinyMCE and Plone Cms with TinyMCE. Our iframe injection on the demo: Insert - Media - Embed - our iframe code. In the demo Plone Cms: Insert - Image - Caption - our iframe code. If a simple user can inject his code into these fields, then he can use it. What can you do with Iframe Injection? Different things. More often this is phishing attack. With Html Injection you can change background and change something what you want. Picture: https://imgur.com/a/IM6PBQh Iframe injection video: https://www.youtube.com/watch?v=KHbhD_zmWcI&feature=youtu.be Html injection video : https://www.youtube.com/watch?v=IoR89uQcbGc&feature=youtu.be


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2020, cxsecurity.com

 

Back to Top