TinyMCE 4.3.8 XSS PoC
As far as I know, if you are using
Preview Plugin
, your application is vulnerable to XSS.
Steps to Reproduce
Open this page using IE/Edge.
Click
here
.
Click "View" menu → "Preview". Done!
test