PT-2021-11270 · Formstone · Formstone
Adriano Monteiro
·
Published
2021-01-07
·
Updated
2022-05-24
·
CVE-2020-26768
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Formstone versions 1.4.16 and earlier
Description:
The issue is caused by improper validation of user-supplied input in the
upload-target.php and upload-chunked.php files, leading to a Reflected Cross-Site Scripting (XSS) vulnerability. A remote attacker could exploit this vulnerability using a specially crafted URL to execute a script in a victim's Web browser within the security context of the hosting Web site once the URL is clicked or visited. This could allow the attacker to steal the victim's cookie-based authentication credentials, force malware execution, or perform user redirection.Recommendations:
For Formstone versions 1.4.16 and earlier, consider disabling the
upload-target.php and upload-chunked.php files as a temporary workaround until a patch is available. Restrict access to these files to minimize the risk of exploitation. Avoid using specially crafted URLs that could trigger the vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability.XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Formstone