ZeroHour

CVE-2024-22220

CVSS 3.1
6.3 medium
EPSS
<1%p30
Published
()
Modified
Description

An issue was discovered in Terminalfour 7.4 through 7.4.0004 QP3 and 8 through 8.3.19, and Formbank through 2.1.10-FINAL. Unauthenticated Stored Cross-Site Scripting can occur, with resultant Admin Session Hijacking. The attack vectors are Form Builder and Form Preview.

Vendors
terminalfour
Products
formbank, terminalfour
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.