Vulnerability Database
Blog
FAQ
Docs
CVE-2023-41592
See a problem?
Please try reporting it
to the source
first.
Source
https://nvd.nist.gov/vuln/detail/CVE-2023-41592
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-41592.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-41592
Aliases
GHSA-hvpq-7vcc-5hj5
Published
2023-09-14T23:15:08Z
Modified
2024-10-12T11:04:56.713874Z
Severity
5.4 (Medium)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS Calculator
Summary
[none]
Details
Froala Editor v4.0.1 to v4.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability.
References
https://hacker.soarescorp.com/cve/2023-41592/
https://owasp.org/Top10/A03_2021-Injection/
https://owasp.org/www-project-top-ten/
Affected packages
Git
/
github.com/froala/wysiwyg-editor
Affected ranges
Type
GIT
Repo
https://github.com/froala/wysiwyg-editor
Events
Introduced
7de2dc8d0ee9404d8df158a104fd0a128d6063aa
Last affected
b724a92f9441f28558b9344e77f71bb1be36079f
Affected versions
v4.*
v4.0.1
v4.0.10
v4.0.11
v4.0.12
v4.0.13
v4.0.14
v4.0.15
v4.0.16
v4.0.17
v4.0.18
v4.0.19
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.1
CVE-2023-41592 - OSV