
We found results for “”
CVE-2024-35621
Good to know:

Date: May 28, 2024
A cross-site scripting (XSS) vulnerability in the Edit function of Formwork before 1.13.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Content field.
Language: PHP
Severity Score
Related Resources (6)
Severity Score
Weakness Type (CWE)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79Top Fix

Upgrade Version
Upgrade to version getformwork/formwork - dev-feature/text-input-icons;getformwork/formwork - dev-ignore-panel-assets;getformwork/formwork - dev-feature/handle-site-post-data;getformwork/formwork - dev-process-file-uploads;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/braces-3.0.3;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/stylelint-scss-6.5.1;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/postcss-8.4.39;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/stylelint-scss-6.3.0;getformwork/formwork - dev-feature/proper-file-responses;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/prettier-3.3.0;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/typescript-5.5.4;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/codemirror-5.65.17;getformwork/formwork - dev-dependabot/composer/jaybizzle/crawler-detect-1.2.119;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/typescript-eslint-8.16.0;getformwork/formwork - dev-dependabot/composer/rector/rector-1.2.2;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/eslint/plugin-kit-0.2.3;getformwork/formwork - dev-dependabot/composer/phpstan/phpstan-1.11.3;getformwork/formwork - dev-feature/invalid-value-exception;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/esbuild-0.21.4;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/sortablejs-1.15.3;getformwork/formwork - dev-dependabot/composer/rector/rector-1.2.0;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/prettier-3.3.2;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/stylelint-scss-6.4.1;getformwork/formwork - dev-feature/sanitizer;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/typescript-eslint-7.11.0;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/eslint-8.57.1;getformwork/formwork - dev-dependabot/composer/rector/rector-2.0.7;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/sass-1.77.4;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/prosemirror-commands-1.6.2;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/globals-15.7.0;getformwork/formwork - dev-php-8.3;getformwork/formwork - dev-dependabot/composer/jaybizzle/crawler-detect-1.3.1;getformwork/formwork - dev-dependabot/composer/league/climate-3.9.0;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/typescript-eslint-8.12.2;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/typescript-eslint-8.22.0;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/typescript-5.7.2;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/micromatch-4.0.8;getformwork/formwork - dev-translations/polish-and-ukrainian;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/prosemirror-view-1.35.0;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/eslint-9.17.0;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/globals-15.12.0;getformwork/formwork - dev-dependabot/composer/friendsofphp/php-cs-fixer-3.58.1;getformwork/formwork - dev-dependabot/composer/league/climate-3.10.0;getformwork/formwork - dev-dependabot/composer/league/commonmark-2.5.1;getformwork/formwork - dev-feature/improved-fields;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/prettier-3.4.2;getformwork/formwork - dev-feature/orderable-tag-input;getformwork/formwork - dev-dependabot/composer/phpstan/phpstan-1.12.0;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/codemirror/lang-markdown-6.3.2;getformwork/formwork - dev-feature/new-modals-api;getformwork/formwork - dev-dependabot/composer/symfony/process-7.1.0;getformwork/formwork - dev-dependabot/composer/phpstan/phpstan-1.12.2;getformwork/formwork - dev-dependabot/composer/symfony/process-7.1.1;getformwork/formwork - dev-feature/file-meta;getformwork/formwork - dev-dependabot/composer/jaybizzle/crawler-detect-1.3.0;getformwork/formwork - no_fix
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | HIGH |
User Interaction (UI): | REQUIRED |
Scope (S): | CHANGED |
Confidentiality (C): | LOW |
Integrity (I): | LOW |
Availability (A): | NONE |