CVE-2020-4061

LOW

October < 1.0.467 - XSS

Title source: rule
STIX 2.1

Description

In October from version 1.0.319 and before version 1.0.467, pasting content copied from malicious websites into the Froala richeditor could result in a successful self-XSS attack. This has been fixed in 1.0.467.

References (3)

Core 3

Scores

CVSS v3 3.7
EPSS 0.0031
EPSS Percentile 54.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
october/backend 1.0.319 - 1.0.467Packagist
octobercms/october 1.0.319 - 1.0.467
Published Jul 02, 2020
Tracked Since Feb 18, 2026