6.5

CVE-2023-6830

Formidable Forms <= 6.7 - HTML Injection

Formidable Forms <= 6.7 - HTML Injection

The Formidable Forms plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 6.7. This vulnerability allows unauthenticated users to inject arbitrary HTML code into form fields. When the form data is viewed by an administrator in the Entries View Page, the injected HTML code is rendered, potentially leading to admin area defacement or redirection to malicious websites. CVE-2024-23522 appears to be a duplicate of this issue.
Mögliche Gegenmaßnahme
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More: Update to version 6.7.1, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Strategy11Formidable Form Builder SwPlatformwordpress Version <= 6.7
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More
Version *-6.7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.309
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
security@wordfence.com 6.5 3.9 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3017166%40formidable%2Ftrunk&old=3009066%40formidable%2Ftrunk&sfp_email=&sfph_mail=
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/ff294b0f-97fe-4d27-bf93-f5bbb57ac1f6?source=cve
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/ff294b0f-97fe-4d27-bf93-f5bbb57ac1f6
Third Party Advisory