XSS exists in the WebForms Pro M2 extension before 2.9.17 for Magento 2 via the textarea field.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://mageme.com/magento-2-form-builder.html | product third party advisory |
https://anothernetsecblog.com/magento-2-extension-security/ | url repurposed third party advisory exploit |