CVE-2020-4061: Cross-site Scripting in OctoberPotential self-XSS when pasting content from malicious websites
In October from version 1.0.319 and before version 1.0.467, pasting content copied from malicious websites into the Froala richeditor could result in a successful self-XSS attack. This has been fixed in 1.0.467.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-4061?
CVE-2020-4061 is a vulnerability in October CMS that allowed self-XSS attacks when pasting content copied from malicious websites into the Froala richeditor.
How severe is CVE-2020-4061?
CVE-2020-4061 has a severity rating of 5.4 (medium).
How can I fix CVE-2020-4061?
To fix CVE-2020-4061, update October CMS to version 1.0.467 or later.
Is there a security advisory for CVE-2020-4061?
Yes, there is a security advisory for CVE-2020-4061. You can find it at the following link: [GitHub Security Advisory](https://github.com/octobercms/october/security/advisories/GHSA-3pc2-fm7p-q2vg)
Is there more information about CVE-2020-4061?
Yes, you can find more information about CVE-2020-4061 at the following links: [GitHub Commit](https://github.com/octobercms/october/commit/b384954a29b89117e1c0d6035b3ede4f46df67c5), [Securitum Research](https://research.securitum.com/the-curious-case-of-copy-paste/)