Impact
Formwork before version 2.3.11 contains a stored cross‑site scripting flaw in visit tracking that records the Referer header host without escaping it. An unauthenticated attacker can send a crafted Referer header containing malicious markup. When an administrator later views the Statistics panel, the stored markup is rendered and executed in the admin’s browser, enabling the attacker to run arbitrary JavaScript with the administrator’s privileges, potentially exposing sensitive data or performing actions on the administrator’s behalf.
Affected Systems
The vulnerability affects all releases of the Formwork application prior to version 2.3.11. Versions 2.3.11 and newer have implemented proper escaping of the Referer header in visit tracking, so they are not impacted.
Risk and Exploitability
The CVSS score of 5.3 places the flaw in the moderate range. EPSS score of 0.00211 and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires network access to the Formwork instance and the ability to set an HTTP Referer header, which a client can do at will. The attack vector is therefore remote and unauthenticated, but it relies on the attacker being able to persuade a browser to send a malicious Referer header to the target.
OpenCVE Enrichment