CyberRota Analysis
AI-GeneratedThe vulnerability affects Formwork versions up to 2.3.14, allowing unauthenticated attackers to exploit a stored cross-site scripting flaw in the visit tracking feature. By crafting malicious Referer headers, attackers can inject executable markup that runs in the browsers of administrators accessing the Statistics panel, potentially compromising sensitive data or session integrity. Organizations using affected versions should prioritize patching this vulnerability to safeguard against potential attacks targeting administrative interfaces.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Formwork before 2.3.11 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer header host unescaped. Unauthenticated attackers can craft malicious Referer headers to inject markup that executes in administrator browsers when viewing the Statistics panel.