VDB
Sign up
MEDIUM4.7

GHSA-vf6x-59hh-332f

Formwork has a cross-site scripting (XSS) vulnerability in Site title

Quick fix

GHSA-vf6x-59hh-332f — getformwork/formwork: upgrade to the fixed version with the command below.

composer require getformwork/formwork:^2.0.0-beta.4

Details

### Summary

The site title field at /panel/options/site/allows embedding JS tags, which can be used to attack all members of the system. This is a widespread attack and can cause significant damage if there is a considerable number of users.

### Impact

The attack is widespread, leveraging what XSS can do. This will undoubtedly impact system availability.

### Patches - [**Formwork 2.x** (aa3e9c6)](https://github.com/getformwork/formwork/commit/aa3e9c684035d9e8495169fde7c57d97faa3f9a2) escapes site title from panel header navigation.

### Details

By embedding "<!--", the source code can be rendered non-functional, significantly impacting system availability. However, the attacker would need admin privileges, making the attack more difficult to execute.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/getformwork/formwork
Introduced in: 2.0.0-beta.3Fixed in: 2.0.0-beta.4
Fixcomposer require getformwork/formwork:^2.0.0-beta.4

References