No CVSS.
rix is a what-you-see-is-what-you-get rich text editor for everyday writing. Versions prior to 2.1.15 are vulnerable to XSS attacks when pasting malicious code. An attacker could trick a user to copy and paste malicious code that would execute arbitrary JavaScript code within the context of the user's session, potentially leading to unauthorized actions being performed or sensitive information being disclosed. This issue has been patched in version 2.1.15.
No configuration.
12 May 2025, 17:32
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
08 May 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2025-05-08 20:15
Updated : 2025-05-12 17:32
NVD link : CVE-2025-46812
Mitre link : CVE-2025-46812
CVE.ORG link : CVE-2025-46812
JSON object : View
No product.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')