PT-2025-41231 · Jhumanj · Jhumanj Opnform

Balejin

·

Published

2025-10-08

·

Updated

2025-10-08

·

CVE-2025-11437

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions JhumanJ OpnForm versions up to 1.9.3
Description A flaw exists in JhumanJ OpnForm up to version 1.9.3, specifically within the Form Editor component. This issue involves manipulation of the /api/open/forms/ file, leading to cross site scripting. The attack can be initiated remotely. The vendor has indicated the feature is disabled until a user configures their own domain, which will mitigate the attack vector.
Recommendations Ensure a custom domain is configured to mitigate the attack vector.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-11437

Affected Products

Jhumanj Opnform