Description
A reflected cross-site scripting (XSS) vulnerability in the grid_datasource.php component of AppNitro MachForm v30 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted payload into the filter[filters][0][field] parameter.
Published: 2026-09-08
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Reflected Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

A reflected cross‑site scripting flaw resides in the grid_datasource.php component of AppNitro MachForm v30. By supplying a malicious payload in the filter[filters][0][field] parameter, an attacker can cause the application to echo the value back to the browser, where it is executed as JavaScript. Such execution permits session hijacking, credential theft, defacement, or the launch of additional malicious code. The weakness maps to CWE‑79.

Affected Systems

Only AppNitro MachForm version 30 is affected; no other vendors or product lines are implicated in the advisory.

Risk and Exploitability

The vulnerability does not require authentication or privileged access; any user who visits a crafted URL or submits a malicious form can trigger it. The likely attack vector depends on user interaction, making phishing or compromised sites common delivery methods. The EPSS score is < 1% and the flaw is not listed in the CISA KEV catalog, yet the combination of ease of exploitation and potential for significant impact keeps the overall risk high for any site running the vulnerable application.

Generated by OpenCVE AI on September 10, 2026 at 04:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s latest patch or upgrade to a fixed version of AppNitro MachForm
  • Validate and sanitize all user input for the filter[filters][0][field] parameter before echoing it to a page
  • Implement a Content Security Policy to restrict inline script execution and mitigate the effect of any remaining XSS vectors

Generated by OpenCVE AI on September 10, 2026 at 04:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Title Reflected XSS in AppNitro MachForm v30 grid_datasource.php

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Tue, 08 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Appnitro
Appnitro machform
Vendors & Products Appnitro
Appnitro machform

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Title Reflected Cross‑Site Scripting via filter Parameters in AppNitro MachForm v30 Reflected XSS in AppNitro MachForm v30 grid_datasource.php

Tue, 08 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Title Reflected Cross‑Site Scripting via filter Parameters in AppNitro MachForm v30
Weaknesses CWE-79

Tue, 08 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description A reflected cross-site scripting (XSS) vulnerability in the grid_datasource.php component of AppNitro MachForm v30 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted payload into the filter[filters][0][field] parameter.
References

Subscriptions

Appnitro Machform
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-09T19:47:55.202Z

Reserved: 2026-08-25T00:00:00.000Z

Link: CVE-2026-78838

cve-icon Vulnrichment

Updated: 2026-09-09T19:47:12.471Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T14:17:28.200

Modified: 2026-09-09T20:20:42.387

Link: CVE-2026-78838

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T04:30:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')