Reflected Cross-Site Scripting Vulnerability in HTML Forms Plugin by Patchstack
CVE-2024-56060

7.1HIGH

Key Information:

Vendor
Html Forms
Status
Html Forms
Vendor
CVE Published:
2 January 2025

Summary

An improper neutralization of input during web page generation leads to a reflected Cross-Site Scripting (XSS) vulnerability in the HTML Forms Plugin by Patchstack. This vulnerability allows attackers to inject malicious scripts into web pages viewed by users. It affects the HTML Forms Plugin from versions n/a through 1.4.1, potentially compromising user data and application integrity. Ensuring proper validation and sanitization of user inputs in forms is crucial to mitigate this risk.

Affected Version(s)

HTML Forms <= 1.4.1

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Thaleikis (Patchstack Alliance)
.