CVE-2024-23522

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Strategy11 Form Builder Team Formidable Forms allows Code Injection.This issue affects Formidable Forms: from n/a through 6.7.
Configurations

Configuration 1 (hide)

cpe:2.3:a:strategy11:formidable_forms:*:*:*:*:free:wordpress:*:*

History

03 Feb 2025, 16:20

Type Values Removed Values Added
References () https://patchstack.com/database/vulnerability/formidable/wordpress-formidable-forms-plugin-6-7-content-injection-vulnerability?_s_id=cve - () https://patchstack.com/database/vulnerability/formidable/wordpress-formidable-forms-plugin-6-7-content-injection-vulnerability?_s_id=cve - Third Party Advisory
CPE cpe:2.3:a:strategy11:formidable_forms:*:*:*:*:free:wordpress:*:*
First Time Strategy11 formidable Forms
Strategy11
CWE CWE-79

21 Nov 2024, 08:57

Type Values Removed Values Added
References () https://patchstack.com/database/vulnerability/formidable/wordpress-formidable-forms-plugin-6-7-content-injection-vulnerability?_s_id=cve - () https://patchstack.com/database/vulnerability/formidable/wordpress-formidable-forms-plugin-6-7-content-injection-vulnerability?_s_id=cve -
Summary
  • (es) neutralización incorrecta de etiquetas HTML relacionadas con scripts en una vulnerabilidad de página web (XSS básico) en Strategy11 Form Builder Team Formidable Forms permite la inyección de código. Este problema afecta a Formidable Forms: desde n/a hasta 6.7.

17 May 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-17 09:15

Updated : 2025-02-03 16:20


NVD link : CVE-2024-23522

Mitre link : CVE-2024-23522

CVE.ORG link : CVE-2024-23522


JSON object : View

Products Affected

strategy11

  • formidable_forms
CWE
CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')