6.1
CVSSv3

CVE-2023-42426

Published: 25/09/2023 Updated: 26/09/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Froala Froala Editor v.4.1.1 allows remote malicious users to execute arbitrary code via the 'Insert link' parameter in the 'Insert Image' component.

Vulnerable Product Search on Vulmon Subscribe to Product

froala froala editor 4.1.1

Github Repositories

Repository for CVE-2023-42426 vulnerability.

CVE ID: CVE-2023-42426 Vulnerability Type: Cross-Site Scripting Description: Cross-site scripting (XSS) vulnerability in Froala Froala Editor v411 allows remote attackers to execute arbitrary code via the 'Insert link' parameter in the 'Insert Image' component Steps to reproduce: Select the "Insert Image" option and add a new image Click on t