Stored XSS Vulnerability in Formafzar Plugin by Instaform
CVE-2025-22524
6.5MEDIUM
Key Information:
- Vendor
- Instaform.ir
- Status
- فرم ساز فرم افزار
- Vendor
- CVE Published:
- 7 January 2025
Summary
The Formafzar plugin developed by Instaform is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. This flaw occurs due to improper neutralization of user input when generating web pages, allowing malicious scripts to be stored and executed within the application. This could allow attackers to execute arbitrary code in the users' sessions, potentially compromising sensitive data and user interactions. The vulnerability affects versions from n/a through 2.0. To safeguard against exploitation, it is crucial for users to keep their plugins updated and implement proper security measures.
Affected Version(s)
فرم ساز فرم افزار <= 2.0
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
zaim (Patchstack Alliance)