PT-2025-41231 · Jhumanj · Jhumanj Opnform
Balejin
·
Published
2025-10-08
·
Updated
2025-10-08
·
CVE-2025-11437
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
JhumanJ OpnForm versions up to 1.9.3
Description
A flaw exists in JhumanJ OpnForm up to version 1.9.3, specifically within the Form Editor component. This issue involves manipulation of the
/api/open/forms/ file, leading to cross site scripting. The attack can be initiated remotely. The vendor has indicated the feature is disabled until a user configures their own domain, which will mitigate the attack vector.Recommendations
Ensure a custom domain is configured to mitigate the attack vector.
Exploit
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jhumanj Opnform