CVE 编号: CVE-2023-42426
漏洞类型: 跨站脚本
描述: Froala Froala Editor v.4.1.1 中的跨站脚本(XSS)漏洞允许远程攻击者通过“插入图像”组件中的“插入链接”参数执行任意代码。
复现步骤:
- 选择“插入图像”选项并添加一张新图像。
- 点击已添加的图像,然后使用“插入链接”选项并输入载荷: https://example.com" onmouseover='alert(xss)'。

参考:
- https://cve.report/CVE-2023-42426
- https://github.com/froala/wysiwyg-editor/issues/4678
- https://froala.com