Junglewise Threat Intelligence

CVE-2020-26768: Formstone reflected XSS in upload file handling

CVE-2020-26768 · Severity: low · CVSS 3.1 · Published 2022-05-24

Vendors: npm.

Executive brief

Formstone is a JavaScript library used for form interactions and file uploads. Versions up to 1.4.16 contain a reflected cross-site scripting (XSS) vulnerability in the file upload components that could allow an attacker to steal user session cookies, redirect users to malicious sites, or execute malware through a crafted URL.

Technical details

Formstone versions 1.4.16 and earlier are vulnerable to reflected XSS (CWE-79) in the upload-target.php and upload-chunked.php files due to improper validation of user-supplied input. The vulnerability is triggered via a specially crafted URL and requires user interaction (clicking/visiting a malicious link). An attacker can exploit this to execute arbitrary JavaScript in the victim's browser within the context of the hosting website, potentially stealing authentication credentials or redirecting to malicious sites. The vulnerability was fixed in version 1.4.17.

Affected products

  • Formstone Formstone <=1.4.16

Timeline

  • 2020-10-02: disclosed: Vulnerability reported via GitHub issue
  • 2022-05-24: advisory: GHSA advisory published
  • 2020: patched: Fixed in version 1.4.17

References