PT-2023-5610 · Froala · Froala Editor

B0Marek

·

Published

2023-09-26

·

Updated

2023-09-29

·

CVE-2023-43263

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Froala Editor version 4.1.1
Description A Cross-site scripting (XSS) issue exists due to insufficient protection of the web page structure. This allows a remote attacker to execute arbitrary code via the Markdown component of the Froala Editor.
Recommendations For Froala Editor version 4.1.1, consider disabling the Markdown component as a temporary workaround until a patch is available. Restrict access to the Markdown feature to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

BDU:2023-06265
CVE-2023-43263

Affected Products

Froala Editor