MEDIUM
Froala Editor v4.0.1 to v4.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability
Published Sep 14, 2023
5.4
MEDIUMCVSS 3.1
EPSS 1.04%
Description
Froala Editor v4.0.1 to v4.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability.
Affected products
No data.
- ≥ 4.0.1 · ≤ 4.1.1
No data.
No Red Hat product state for this CVE.
froala/wysiwyg-editor
Packagist
Introduced 4.0.1 Fixed 4.1.4froala-editor
npm
Introduced 4.0.1 Fixed 4.1.4
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Packagist | froala/wysiwyg-editor | 4.0.1 | 4.1.4 |
| npm | froala-editor | 4.0.1 | 4.1.4 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-2529 Advisory
- https://froala.com/wysiwyg-editor/changelog/#4.1.4
- https://github.com/advisories/GHSA-hvpq-7vcc-5hj5 Advisory
- https://github.com/froala/wysiwyg-editor/issues/4612#issuecomment-1729818089
- https://hacker.soarescorp.com/cve/2023-41592 ExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-41592
- https://owasp.org/Top10/A03_2021-Injection Third Party Advisory
- https://owasp.org/www-project-top-ten Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-2529 | Advisory | |
| https://froala.com/wysiwyg-editor/changelog/#4.1.4 | ||
| https://github.com/advisories/GHSA-hvpq-7vcc-5hj5 | Advisory | |
| https://github.com/froala/wysiwyg-editor/issues/4612#issuecomment-1729818089 | ||
| https://hacker.soarescorp.com/cve/2023-41592 | ExploitThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-41592 | ||
| https://owasp.org/Top10/A03_2021-Injection | Third Party Advisory | |
| https://owasp.org/www-project-top-ten | Third Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 14, 2023
Updated Sep 25, 2024
Reserved Aug 30, 2023
Link CVE-2023-41592
CISA Vulnrichment
Updated Sep 25, 2024
ENISA EUVD
EUVD-2023-2529 GHSA-HVPQ-7VCC-5HJ5 Assigner mitre
Published Sep 14, 2023
Updated Sep 25, 2024
Exploited since n/a
Link EUVD-2023-2529