icon

We found results for “

CVE-2024-35621

Good to know:

icon

Date: May 28, 2024

A cross-site scripting (XSS) vulnerability in the Edit function of Formwork before 1.13.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Content field.

Language: PHP

Severity Score

Severity Score

Weakness Type (CWE)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-79

Top Fix

icon

Upgrade Version

Upgrade to version getformwork/formwork - dev-feature/text-input-icons;getformwork/formwork - dev-ignore-panel-assets;getformwork/formwork - dev-feature/handle-site-post-data;getformwork/formwork - dev-process-file-uploads;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/braces-3.0.3;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/stylelint-scss-6.5.1;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/postcss-8.4.39;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/stylelint-scss-6.3.0;getformwork/formwork - dev-feature/proper-file-responses;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/prettier-3.3.0;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/typescript-5.5.4;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/codemirror-5.65.17;getformwork/formwork - dev-dependabot/composer/jaybizzle/crawler-detect-1.2.119;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/typescript-eslint-8.16.0;getformwork/formwork - dev-dependabot/composer/rector/rector-1.2.2;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/eslint/plugin-kit-0.2.3;getformwork/formwork - dev-dependabot/composer/phpstan/phpstan-1.11.3;getformwork/formwork - dev-feature/invalid-value-exception;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/esbuild-0.21.4;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/sortablejs-1.15.3;getformwork/formwork - dev-dependabot/composer/rector/rector-1.2.0;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/prettier-3.3.2;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/stylelint-scss-6.4.1;getformwork/formwork - dev-feature/sanitizer;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/typescript-eslint-7.11.0;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/eslint-8.57.1;getformwork/formwork - dev-dependabot/composer/rector/rector-2.0.7;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/sass-1.77.4;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/prosemirror-commands-1.6.2;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/globals-15.7.0;getformwork/formwork - dev-php-8.3;getformwork/formwork - dev-dependabot/composer/jaybizzle/crawler-detect-1.3.1;getformwork/formwork - dev-dependabot/composer/league/climate-3.9.0;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/typescript-eslint-8.12.2;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/typescript-eslint-8.22.0;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/typescript-5.7.2;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/micromatch-4.0.8;getformwork/formwork - dev-translations/polish-and-ukrainian;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/prosemirror-view-1.35.0;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/eslint-9.17.0;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/globals-15.12.0;getformwork/formwork - dev-dependabot/composer/friendsofphp/php-cs-fixer-3.58.1;getformwork/formwork - dev-dependabot/composer/league/climate-3.10.0;getformwork/formwork - dev-dependabot/composer/league/commonmark-2.5.1;getformwork/formwork - dev-feature/improved-fields;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/prettier-3.4.2;getformwork/formwork - dev-feature/orderable-tag-input;getformwork/formwork - dev-dependabot/composer/phpstan/phpstan-1.12.0;getformwork/formwork - dev-dependabot/npm_and_yarn/panel/codemirror/lang-markdown-6.3.2;getformwork/formwork - dev-feature/new-modals-api;getformwork/formwork - dev-dependabot/composer/symfony/process-7.1.0;getformwork/formwork - dev-dependabot/composer/phpstan/phpstan-1.12.2;getformwork/formwork - dev-dependabot/composer/symfony/process-7.1.1;getformwork/formwork - dev-feature/file-meta;getformwork/formwork - dev-dependabot/composer/jaybizzle/crawler-detect-1.3.0;getformwork/formwork - no_fix

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): HIGH
User Interaction (UI): REQUIRED
Scope (S): CHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): NONE

Do you need more information?

Contact Us