PT-2021-21963 · Unknown · Form Tools
Published
2021-08-31
·
Updated
2021-09-08
·
CVE-2021-38143
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Form Tools versions 3.0.20 and earlier
Description:
An issue was discovered in Form Tools where the customer's name and last name fields are vulnerable to XSS payload insertion. This stored XSS can be triggered in the admin panel when the admin tries to view the client list, potentially leading to the extraction of the admin's PHPSESSID cookie.
Recommendations:
For versions 3.0.20 and earlier, consider disabling the ability for customers to change their name and last name fields until a patch is available. Restrict access to the admin panel to minimize the risk of exploitation. Avoid displaying the client list in the admin panel until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Form Tools