CVE-2024-37160 - CVE House
Back to Database
Status published Medium CVE-2024-37160

Formwork has a Cross-site scripting (XSS) vulnerability in Description metadata

Vulnerability Description

Formwork is a flat file-based Content Management System (CMS). An attackers (requires administrator privilege) to execute arbitrary web scripts by modifying site options via /panel/options/site. This type of attack is suitable for persistence, affecting visitors across all pages (except the dashboard). This vulnerability is fixed in 1.13.1.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-37160

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

getformwork

View all reports →

Affected Software

formwork
Vulnerable Versions:
< 1.13.1, = 2.0.0-beta.1

Timeline

Official Publish: June 7th, 2024
Last Modified: August 2nd, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Weaknesses (CWE)