Reflected Cross-Site Scripting Vulnerability in HTML Forms Plugin by Patchstack
CVE-2024-56060
7.1HIGH
Key Information:
- Vendor
- Html Forms
- Status
- Html Forms
- Vendor
- CVE Published:
- 2 January 2025
Summary
An improper neutralization of input during web page generation leads to a reflected Cross-Site Scripting (XSS) vulnerability in the HTML Forms Plugin by Patchstack. This vulnerability allows attackers to inject malicious scripts into web pages viewed by users. It affects the HTML Forms Plugin from versions n/a through 1.4.1, potentially compromising user data and application integrity. Ensuring proper validation and sanitization of user inputs in forms is crucial to mitigate this risk.
Affected Version(s)
HTML Forms <= 1.4.1
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Peter Thaleikis (Patchstack Alliance)