Логотип exploitDog
bind: "CVE-2023-33971"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2023-33971"

Количество 2

Количество 2

nvd логотип

CVE-2023-33971

около 2 лет назад

Formcreator is a GLPI plugin which allow creation of custom forms and the creation of one or more tickets when the form is filled. A probable stored cross-site scripting vulnerability is present in Formcreator 2.13.5 and prior via the use of the use of `##FULLFORM##` for rendering. This could result in arbitrary javascript code execution in an admin/tech context. A patch is unavailable as of time of publication. As a workaround, one may use a regular expression to remove `< > "` in all fields.

CVSS3: 6.1
EPSS: Низкий
redos логотип

ROS-20240812-02

11 месяцев назад

Уязвимость glpi-plugin-formcreator

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-33971

Formcreator is a GLPI plugin which allow creation of custom forms and the creation of one or more tickets when the form is filled. A probable stored cross-site scripting vulnerability is present in Formcreator 2.13.5 and prior via the use of the use of `##FULLFORM##` for rendering. This could result in arbitrary javascript code execution in an admin/tech context. A patch is unavailable as of time of publication. As a workaround, one may use a regular expression to remove `< > "` in all fields.

CVSS3: 6.1
2%
Низкий
около 2 лет назад
redos логотип
ROS-20240812-02

Уязвимость glpi-plugin-formcreator

CVSS3: 5.4
2%
Низкий
11 месяцев назад

Уязвимостей на страницу