Description
A flaw has been found in JhumanJ OpnForm up to 1.9.3. This affects an unknown part of the file /api/open/forms/ of the component Form Editor. This manipulation causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used. This issue is currently under review for additional handling. As of right now the vendor has stated that the feature is disabled until the user has configured their own domain which will mitigate this attack vector.
In JhumanJ OpnForm up to 1.9.3 wurde eine Schwachstelle gefunden. Betroffen davon ist ein unbekannter Prozess der Datei /api/open/forms/ der Komponente Form Editor. Die Veränderung resultiert in cross site scripting. Umgesetzt werden kann der Angriff über das Netzwerk. Die Ausnutzung wurde veröffentlicht und kann verwendet werden.
Problem types
Product status
1.9.1
1.9.2
1.9.3
Timeline
2025-10-07: | Advisory disclosed |
2025-10-07: | VulDB entry created |
2025-10-07: | VulDB entry last update |
Credits
balejin (VulDB User)
References
vuldb.com/?id.327374 (VDB-327374 | JhumanJ OpnForm Form Editor forms cross site scripting)
vuldb.com/?ctiid.327374 (VDB-327374 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.666878 (Submit #666878 | GitHub OpnForm 1.9.3 Cross Site Scripting)
docs.google.com/...v6ySsbCIhVynf8_djardLZYEDOe0/edit?tab=t.0