CVE-2024-35621: formwork Cross-site scripting vulnerability in Markdown fields
Users with access to the administration panel with page editing permissions could insert <script>
tags in markdown fields, which are exposed on the publicly accessible site pages, leading to potential XSS injections.
References
- github.com/advisories/GHSA-gx8m-f3mp-fg99
- github.com/getformwork/formwork
- github.com/getformwork/formwork/commit/2d92e6dbf99a9a49797947afbda0cdd4e56e11df
- github.com/getformwork/formwork/commit/6adc302f5a294f2ffbbf1571dd4ffea6b7876723
- github.com/getformwork/formwork/security/advisories/GHSA-gx8m-f3mp-fg99
- nvd.nist.gov/vuln/detail/CVE-2024-35621
Detect and mitigate CVE-2024-35621 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →