Form Builder 2.1.0 for Magento has multiple XSS issues that can be exploited against Magento 2 admin accounts via the Current_url or email field, or the User-Agent HTTP header.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://anothernetsecblog.com | third party advisory url repurposed |
https://landofcoder.com/magento-2-form-builder.html | third party advisory product |
https://anothernetsecblog.com/magento-2-extension-security/ | url repurposed exploit third party advisory |