Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:43319
HistorySep 20, 2023 - 8:07 a.m.

Cross Site Scripting

2023-09-2008:07:23
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14
froala
wysiwyg
software
vulnerability
cross site scripting
insert link

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

26.6%

froala-editor & froala/wysiwyg-editor is vulnerable to Cross Site Scripting. The vulnerability is due to the Insert Link functionality which does not properly sanitize or validate the link that user provides, resulting in Cross Site Scripting.

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

26.6%