CVE-2023-42426
MEDIUMFroala Editor 4.1.1 - Stored Cross-Site Scripting via Insert Link Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-42426. PoCs published by b0marek.
AI-analyzed exploit summary This repository provides a detailed writeup of CVE-2023-42426, a stored XSS vulnerability in Froala Editor v4.1.1. It includes steps to reproduce the issue via the 'Insert Link' parameter in the 'Insert Image' component, along with references to external sources.
Description
Cross-site scripting (XSS) vulnerability in Froala Froala Editor v.4.1.1 allows remote attackers to execute arbitrary code via the 'Insert link' parameter in the 'Insert Image' component.
Exploits (1)
This repository provides a detailed writeup of CVE-2023-42426, a stored XSS vulnerability in Froala Editor v4.1.1. It includes steps to reproduce the issue via the 'Insert Link' parameter in the 'Insert Image' component, along with references to external sources.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N