6.1
CVSSv3

CVE-2023-43263

Published: 27/09/2023 Updated: 29/09/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A Cross-site scripting (XSS) vulnerability in Froala Editor v.4.1.1 allows malicious users to execute arbitrary code via the Markdown component.

Vulnerable Product Search on Vulmon Subscribe to Product

froala froala editor 4.1.1

Github Repositories

Repository for CVE-2023-43263 vulnerability.

CVE ID: CVE-2023-43263 Vulnerability Type: Cross-Site Scripting Description: Cross-site scripting (XSS) vulnerability in Froala Editor v411 allows attackers to execute arbitrary code via the Markdown component Steps to reproduce: Enter payload in markdown component input: <a title ="a <img src=x onerror=consolelog(documentcookie)>xss</a&a