Impact
The flaw exists because HTML-FormHandler renders error messages by directly inserting the error string into HTML without any escaping. Two internal messages, named no_match and not_allowed, embed the user‑supplied value into the string, and a type constraint that fails also places the rejected value into the message built by _apply_actions. When an attacker submits markup to a field that uses a regular‑expression check, a check list, or a type constraint without a custom validator or altered configuration, the resulting error string is injected into the page exactly as submitted. The reflected cross‑site scripting vulnerability allows the execution of arbitrary scripts in the victim’s browser context, actions within the target domain.
Affected Systems
This vulnerability affects every installation of the Perl HTML‑FormHandler library with a version older than 0.410000. The issue is tied to the library’s own wrappers and renderers that interpolate error strings directly into HTML. Applications employing the library’s error rendering roles, or using a different error‑display mechanism that performs its own escaping, are not affected. Any application that relies on the default error rendering and provides unescaped values in form validation is vulnerable.
Risk and Exploitability
The vulnerability can be exploited via a normal form submission that triggers a validation failure. Based attacker would submit markup over the network to a field that uses a regular‑expression check, a check list, or a type constraint without a custom validator, causing the library to embed the unescaped value in an error string. This inferred attack vector exploits the library’s default error rendering. The EPSS score is < 1% and the KEV status is not listed, indicating a low overall probability of exploitation, but the clear path to reflected XSS and the fact that it does not require elevated privileges suggest a high risk to any user who interacts with such forms. The CVSS score of 6.1 signals medium severity, the reflected XSS flaw that permits arbitrary client‑side code execution.
OpenCVE Enrichment