PT-2023-9942 · Unknown · Php-Form-Builder-Class

Manikandan170890

·

Publicado

2023-01-12

·

Atualizado

2024-05-17

·

CVE-2012-10005

CVSS v2.0

4.0

Média

VetorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions manikandan170890 php-form-builder-class (affected versions not specified)
Description A vulnerability has been found in the Textarea Handler component of the php-form-builder-class, specifically in the file PFBC/Element/Textarea.php. The manipulation of the value argument leads to cross-site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Recommendations To fix this issue, it is recommended to apply the patch named 74897993818d826595fd5857038e6703456a594a. As a temporary workaround, consider restricting access to the Textarea Handler component until the patch is applied. Avoid using the value argument in the affected functionality until the issue is resolved.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-10005

Produtos afetados

Php-Form-Builder-Class