CVE-2023-42426

MEDIUM

Froala Editor 4.1.1 - Stored Cross-Site Scripting via Insert Link Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-42426. PoCs published by b0marek.

AI-analyzed exploit summary This repository provides a detailed writeup of CVE-2023-42426, a stored XSS vulnerability in Froala Editor v4.1.1. It includes steps to reproduce the issue via the 'Insert Link' parameter in the 'Insert Image' component, along with references to external sources.

Description

Cross-site scripting (XSS) vulnerability in Froala Froala Editor v.4.1.1 allows remote attackers to execute arbitrary code via the 'Insert link' parameter in the 'Insert Image' component.

Exploits (1)

nomisec WRITEUP
by b0marek · poc
https://github.com/b0marek/CVE-2023-42426

This repository provides a detailed writeup of CVE-2023-42426, a stored XSS vulnerability in Froala Editor v4.1.1. It includes steps to reproduce the issue via the 'Insert Link' parameter in the 'Insert Image' component, along with references to external sources.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Froala Editor v4.1.1
No auth needed
Prerequisites: Access to a vulnerable instance of Froala Editor
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Scores

CVSS v3 6.1
EPSS 0.0105
EPSS Percentile 59.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
froala/froala_editor 4.1.1
Published Sep 25, 2023
Tracked Since Feb 18, 2026