CVE-2024-37160

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
07/06/2024
Last modified:
11/06/2024

Description

Formwork is a flat file-based Content Management System (CMS). An attackers (requires administrator privilege) to execute arbitrary web scripts by modifying site options via /panel/options/site. This type of attack is suitable for persistence, affecting visitors across all pages (except the dashboard). This vulnerability is fixed in 1.13.1.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:formwork_project:formwork:*:*:*:*:*:*:*:* 1.13.1 (excluding)