First published: Tue Sep 26 2023(Updated: )
A Cross-site scripting (XSS) vulnerability in Froala Editor v.4.1.1 allows attackers to execute arbitrary code via the Markdown component.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Froala WYSIWYG Editor | =4.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-43263 is medium with a score of 6.1.
The affected software in CVE-2023-43263 is Froala Editor v.4.1.1.
The CWE category of CVE-2023-43263 is CWE-79 (Cross-site Scripting).
An attacker can exploit CVE-2023-43263 by executing arbitrary code via the Markdown component of Froala Editor v.4.1.1.
Yes, you can find references for CVE-2023-43263 at the following links: [GitHub](https://github.com/b0marek/CVE-2023-43263) and [YouTube](https://www.youtube.com/watch?v=-dXipo_q7tM).