{"id":"GHSA-hvpq-7vcc-5hj5","summary":"Froala Editor Cross-site Scripting vulnerability","details":"Froala Editor v4.0.1 to v4.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability.","aliases":["CVE-2023-41592"],"modified":"2025-03-14T15:00:59.221827Z","published":"2023-09-15T00:30:29Z","database_specific":{"github_reviewed_at":"2023-09-15T19:02:52Z","nvd_published_at":"2023-09-14T23:15:08Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-41592"},{"type":"WEB","url":"https://github.com/froala/wysiwyg-editor/issues/4612#issuecomment-1729818089"},{"type":"WEB","url":"https://froala.com/wysiwyg-editor/changelog/#4.1.4"},{"type":"PACKAGE","url":"https://github.com/froala/wysiwyg-editor"},{"type":"WEB","url":"https://hacker.soarescorp.com/cve/2023-41592"},{"type":"WEB","url":"https://owasp.org/Top10/A03_2021-Injection"},{"type":"WEB","url":"https://owasp.org/www-project-top-ten"}],"affected":[{"package":{"name":"froala/wysiwyg-editor","ecosystem":"Packagist","purl":"pkg:composer/froala/wysiwyg-editor"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.1"},{"fixed":"4.1.4"}]}],"versions":["v4.0.1","v4.0.10","v4.0.11","v4.0.12","v4.0.13","v4.0.14","v4.0.15","v4.0.16","v4.0.17","v4.0.18","v4.0.19","v4.0.2","v4.0.3","v4.0.4","v4.0.5","v4.0.6","v4.0.7","v4.0.8","v4.0.9","v4.1.0","v4.1.1","v4.1.2","v4.1.3"],"database_specific":{"last_known_affected_version_range":"\u003c= 4.1.3","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/09/GHSA-hvpq-7vcc-5hj5/GHSA-hvpq-7vcc-5hj5.json"}},{"package":{"name":"froala-editor","ecosystem":"npm","purl":"pkg:npm/froala-editor"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.0.1"},{"fixed":"4.1.4"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 4.1.3","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/09/GHSA-hvpq-7vcc-5hj5/GHSA-hvpq-7vcc-5hj5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}