Junglewise Threat Intelligence

CVE-2023-41592: Froala Editor cross-site scripting vulnerability

CVE-2023-41592 · Severity: low · CVSS 3.1 · Published 2023-09-15

Technologies: froala-editor (npm), Froala Editor, froala/wysiwyg-editor (Packagist). Vendors: npm, Froala, Packagist.

Executive brief

Froala Editor is a rich-text document editor used in web applications to allow users to create and format content. Versions 4.0.1 through 4.1.3 contain a cross-site scripting (XSS) vulnerability that allows attackers with editor access to inject malicious scripts that execute in other users' browsers, potentially compromising account credentials, stealing session tokens, or defacing content.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in Froala Editor versions 4.0.1 to 4.1.3, classified as CWE-79. The vulnerability allows an authenticated or privileged user to inject malicious JavaScript through the editor interface that persists when the content is viewed by other users. Attack requires user interaction (opening the edited content) and authentication to use the editor, but impact spans across sessions (C:L, I:L per CVSS 3.1). The vulnerability was patched in version 4.1.4.

Affected products

  • Froala Editor 4.0.1 to 4.1.3

Timeline

  • 2023-09-14: disclosed: CVE-2023-41592 published
  • 2023: patched: Fixed in version 4.1.4

References

Related threats