PT-2023-9942 · Unknown · Php-Form-Builder-Class

Manikandan170890

·

Published

2023-01-12

·

Updated

2024-05-17

·

CVE-2012-10005

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions manikandan170890 php-form-builder-class (affected versions not specified)
Description A vulnerability has been found in the Textarea Handler component of the php-form-builder-class, specifically in the file PFBC/Element/Textarea.php. The manipulation of the value argument leads to cross-site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Recommendations To fix this issue, it is recommended to apply the patch named 74897993818d826595fd5857038e6703456a594a. As a temporary workaround, consider restricting access to the Textarea Handler component until the patch is applied. Avoid using the value argument in the affected functionality until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2012-10005

Affected Products

Php-Form-Builder-Class