First published: Sun Jul 21 2024(Updated: )
A vulnerability classified as problematic was found in formtools.org Form Tools 3.1.1. This vulnerability affects unknown code of the file /admin/clients/ of the component User Settings Page. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-271990 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
MooTools | =3.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-6935 is classified as a problematic vulnerability affecting the User Settings Page of Form Tools 3.1.1.
CVE-2024-6935 leads to cross-site scripting vulnerabilities allowing remote attackers to manipulate the user settings.
CVE-2024-6935 specifically affects the /admin/clients/ section of the User Settings Page in Form Tools 3.1.1.
Yes, CVE-2024-6935 can be exploited remotely to compromise the application through cross-site scripting.
To mitigate CVE-2024-6935, it is recommended to update Form Tools to a version that addresses this vulnerability or implement web application firewalls to filter malicious input.