Jump to content

Recommended Posts

Posted

Hello, I'm new to this forum, but I work at an agency that uses processwire for most of our bespoke sites.  I've started setting up vulnerability scanning on most of our projects and I've discovered that the version of tinyMCE bundled with processwire has some high severity (according to github) vulnerabilities.

These are XSS vulnerabilities so to spell it out this would mean that one admin could steal another admin's session (which I believe is classed as a medium severity issue) or if users can control something that ends up in an admin wysiwyg (idk maybe in a contact form or something) a non-user could steal an admin session (high severity).  They were disclosed in May.

The big problem is: tinyMCE v6 is end of life, and the new versions have a new licence that is not really compatible with projects like processwire.  I've searched the forums and found some discussion of this from a few years ago, but I think I'm the first to raise the subject in a while and perhaps the first to notice these CVEs.

Firstly, I guess I'm just disclosing the issue and warning anyone who uses user data in wysiwyg that they cannot trust tinyMCE and should take action.  Secondly I have a few questions

  • Is there an alternative rich text editor module anyone can recommend?
  • Is there an alternative rich text editor that does not yet exist as a module anyone can recommend?
  • Are there plans to move off tinyMCE in the future?  I appreciate this is going to be a big task.
Posted
33 minutes ago, Sammy said:

Firstly, I guess I'm just disclosing the issue and warning anyone who uses user data in wysiwyg that they cannot trust tinyMCE and should take action

Ah, there is a HTML sanitiser than runs that limits the risk here

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...