PT-2024-19285 · Terminalfour · Formbank+1
Published
2024-02-21
·
Updated
2025-05-08
·
CVE-2024-22220
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Terminalfour versions 7.4 through 7.4.0004 QP3
Terminalfour versions 8 through 8.3.19
Formbank versions through 2.1.10-FINAL
Description
An issue allows Unauthenticated Stored Cross-Site Scripting, potentially leading to Admin Session Hijacking. The attack vectors are the Form Builder and Form Preview.
Recommendations
For Terminalfour versions 7.4 through 7.4.0004 QP3, update to a version outside of this range to mitigate the risk.
For Terminalfour versions 8 through 8.3.19, update to a version outside of this range to mitigate the risk.
For Formbank versions through 2.1.10-FINAL, update to a version later than 2.1.10-FINAL to resolve the issue.
As a temporary workaround, consider restricting access to the Form Builder and Form Preview features until a patch is available.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Formbank
Terminalfour