Stored XSS Vulnerability in Formafzar Plugin by Instaform
CVE-2025-22524

6.5MEDIUM

Key Information:

Vendor
Instaform.ir
Status
فرم ساز فرم افزار
Vendor
CVE Published:
7 January 2025

Summary

The Formafzar plugin developed by Instaform is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. This flaw occurs due to improper neutralization of user input when generating web pages, allowing malicious scripts to be stored and executed within the application. This could allow attackers to execute arbitrary code in the users' sessions, potentially compromising sensitive data and user interactions. The vulnerability affects versions from n/a through 2.0. To safeguard against exploitation, it is crucial for users to keep their plugins updated and implement proper security measures.

Affected Version(s)

فرم ساز فرم افزار <= 2.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zaim (Patchstack Alliance)
.