LOW · 3.7

CVE-2020-4061

In October from version 1.0.319 and before version 1.0.467, pasting content copied from malicious websites into the Froala richeditor could result in a successful self-XSS attack. This has been fixed ...

Vulnerability Description

In October from version 1.0.319 and before version 1.0.467, pasting content copied from malicious websites into the Froala richeditor could result in a successful self-XSS attack. This has been fixed in 1.0.467.

CVSS Score

3.7

LOW

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
OctobercmsOctober>= 1.0.319, < 1.0.467

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-4061?

CVE-2020-4061 is a vulnerability with a CVSS score of 3.7 (LOW). In October from version 1.0.319 and before version 1.0.467, pasting content copied from malicious websites into the Froala richeditor could result in a successful self-XSS attack. This has been fixed ...

How severe is CVE-2020-4061?

CVE-2020-4061 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-4061?

Check the references section above for vendor advisories and patch information. Affected products include: Octobercms October.