Executive brief
Formstone is a JavaScript library used for form interactions and file uploads. Versions up to 1.4.16 contain a reflected cross-site scripting (XSS) vulnerability in the file upload components that could allow an attacker to steal user session cookies, redirect users to malicious sites, or execute malware through a crafted URL.
Technical details
Formstone versions 1.4.16 and earlier are vulnerable to reflected XSS (CWE-79) in the upload-target.php and upload-chunked.php files due to improper validation of user-supplied input. The vulnerability is triggered via a specially crafted URL and requires user interaction (clicking/visiting a malicious link). An attacker can exploit this to execute arbitrary JavaScript in the victim's browser within the context of the hosting website, potentially stealing authentication credentials or redirecting to malicious sites. The vulnerability was fixed in version 1.4.17.
Affected products
- Formstone Formstone <=1.4.16
Timeline
- 2020-10-02: disclosed: Vulnerability reported via GitHub issue
- 2022-05-24: advisory: GHSA advisory published
- 2020: patched: Fixed in version 1.4.17