VDB
Sign up
MEDIUM4.8

GHSA-fvrh-wrpf-6q7h

Formwork Cross-site Scripting (XSS) from Page title field

Quick fix

GHSA-fvrh-wrpf-6q7h — getformwork/formwork: upgrade to the fixed version with the command below.

composer require getformwork/formwork:^1.13.0

Details

### Description A stored cross-site scripting (XSS) vulnerability in Formwork v1.12.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page title field.

Only users with access to Administration Panel with page editing permission can inject raw HTML in the Page title field.

### Patched versions This vulnerability has been patched in [Formwork 1.13.0](https://github.com/getformwork/formwork/releases/tag/1.13.0).

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/getformwork/formwork
Introduced in: 0Fixed in: 1.13.0
Fixcomposer require getformwork/formwork:^1.13.0

References