Formstone Vulnerable to Reflected XSS
Moderate severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Apr 1, 2024
Description
Published by the National Vulnerability Database
Jan 7, 2021
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Apr 1, 2024
Reviewed
Apr 1, 2024
Formstone <=1.4.16 is vulnerable to a Reflected Cross-Site Scripting (XSS) vulnerability caused by improper validation of user supplied input in the
upload-target.php
andupload-chunked.php
files. A remote attacker could exploit this vulnerability using a specially crafted URL to execute a script in a victim's Web browser within the security context of the hosting Web site once the URL is clicked or visited. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials, force malware execution, user redirection and others.References