PT-2020-13530 · Magento · Form Builder+1

Published

2020-06-29

·

Updated

2024-02-14

·

CVE-2020-13423

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Form Builder version 2.1.0 for Magento
Description The issue concerns multiple XSS problems that can be exploited against Magento 2 admin accounts. This can be achieved via the Current url or email field, or the User-Agent HTTP header.
Recommendations For Form Builder version 2.1.0, consider disabling the Current url and email fields, or restricting access to them, until a patch is available. Additionally, as a temporary workaround, restrict the information sent in the User-Agent HTTP header to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-13423

Affected Products

Form Builder
Magento