VulnerabilityModified
CVE-2020-4061
In October from version 1.0.319 and before version 1.0.467, pasting content copied from malicious websites into the Froala richeditor could result in a successful self-XSS attack.
MEDIUM 5.4EPSS 0.82%
Does this matter?
Lower severity and a low EPSS score (0.82%). Track it; it rarely justifies an emergency change on its own.
Description
In October from version 1.0.319 and before version 1.0.467, pasting content copied from malicious websites into the Froala richeditor could result in a successful self-XSS attack. This has been fixed in 1.0.467.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.82% probability · 55th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- octobercms/october
- Source
- security-advisories@github.com
References
- https://github.com/octobercms/october/commit/b384954a29b89117e1c0d6035b3ede4f46df67c5Patch, Third Party Advisory
- https://github.com/octobercms/october/security/advisories/GHSA-3pc2-fm7p-q2vgThird Party Advisory
- https://research.securitum.com/the-curious-case-of-copy-paste/Exploit, Third Party Advisory
- https://github.com/octobercms/october/commit/b384954a29b89117e1c0d6035b3ede4f46df67c5Patch, Third Party Advisory
- https://github.com/octobercms/october/security/advisories/GHSA-3pc2-fm7p-q2vgThird Party Advisory
- https://research.securitum.com/the-curious-case-of-copy-paste/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.