{"id":"CVE-2020-4061","aliases":["GHSA-3pc2-fm7p-q2vg"],"url":"https://o3.security/vulnerability/CVE-2020-4061","summary":"Cross-site Scripting in October","details":"In October from version 1.0.319 and before version 1.0.467, pasting content copied from malicious websites into the Froala richeditor could result in a successful self-XSS attack. This has been fixed in 1.0.467.","published":"2020-07-02T17:15:12.670Z","modified":"2026-08-07T15:12:40.655916Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"},"epss":{"score":0.00821,"percentile":0.54169,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"october/backend","fixedVersion":"1.0.467"}],"fix":{"url":"https://github.com/octobercms/october/commit/b384954a29b89117e1c0d6035b3ede4f46df67c5","label":"octobercms/october@b384954"},"references":[{"type":"ADVISORY","url":"https://github.com/octobercms/october/security/advisories/GHSA-3pc2-fm7p-q2vg"},{"type":"FIX","url":"https://github.com/octobercms/october/commit/b384954a29b89117e1c0d6035b3ede4f46df67c5"},{"type":"EVIDENCE","url":"https://research.securitum.com/the-curious-case-of-copy-paste/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T15:12:40.655916Z"}}