PT-2021-21963 · Unknown · Form Tools

Published

2021-08-31

·

Updated

2021-09-08

·

CVE-2021-38143

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Form Tools versions 3.0.20 and earlier
Description: An issue was discovered in Form Tools where the customer's name and last name fields are vulnerable to XSS payload insertion. This stored XSS can be triggered in the admin panel when the admin tries to view the client list, potentially leading to the extraction of the admin's PHPSESSID cookie.
Recommendations: For versions 3.0.20 and earlier, consider disabling the ability for customers to change their name and last name fields until a patch is available. Restrict access to the admin panel to minimize the risk of exploitation. Avoid displaying the client list in the admin panel until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-38143

Affected Products

Form Tools