ZeroHour

CVE-2023-42426

PoC ×2
CVSS 3.1
6.1 medium
EPSS
<1%p54
Published
()
Modified
Description

Cross-site scripting (XSS) vulnerability in Froala Froala Editor v.4.1.1 allows remote attackers to execute arbitrary code via the 'Insert link' parameter in the 'Insert Image' component.

Vendors
froala
Products
froala editor
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.