CVE Published: 02/07/2020 |
CVE Updated: 04/08/2024 |
CVE Year: 2020 Source: GitHub_M |
Vendor: October CMS |
Product: October Status : PUBLISHED
CVE-2020-4061 Description
In October from version 1.0.319 and before version 1.0.467, pasting content copied from malicious websites into the Froala richeditor could result in a successful self-XSS attack. This has been fixed in 1.0.467.
Metrics
CVSS Version: 3.1 |
Base Score: 3.7 LOW Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N