CVE-2023-42426

MEDIUM

Froala Editor - XSS

Title source: rule
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in Froala Froala Editor v.4.1.1 allows remote attackers to execute arbitrary code via the 'Insert link' parameter in the 'Insert Image' component.

Exploits (1)

nomisec WRITEUP
by b0marek · poc
https://github.com/b0marek/CVE-2023-42426

Scores

CVSS v3 6.1
EPSS 0.0059
EPSS Percentile 69.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
froala/froala_editor 4.1.1
Published Sep 25, 2023
Tracked Since Feb 18, 2026