Impact
HTML::FormHandler versions before 0.410002 generate option group labels and radio button labels directly into the HTML output without escaping. The unescaped labels can contain arbitrary markup or JavaScript code. If an attacker can influence the text that populates these labels—through options_from, options_fieldname, or a DBIC model—the resulting page can execute script code in a user’s browser, altering the form’s appearance or behavior. The vulnerability directly permits the injection of script that may affect any user who visits the page. Based on the description, it is inferred that the attacker must be able to supply the option labels.
Affected Systems
Any Perl application that incorporates the HTML::FormHandler module in a version earlier than 0.410002 is potentially vulnerable. The issue is present in the Select, RadioGroup, CheckboxGroup render the group labels or option labels unescaped. This includes all CPAN releases and derivative packages that have not applied the publisher’s patch or updated to the fixed version. Applications that dynamically generate option lists from user‑supplied data or database models are also affected.
Risk and Exploitability
Based on the description, the likely attack vector is that an attacker can influence the content of a form’s option list via options_from, options_fieldname, or a DBIC model. The security analysis indicates a moderate‑impact XSS flaw, with a CVSS score of 6.1. The EPSS score is less than 1%, and the vulnerability is not listed in CISA KEV, suggesting limited observed exploitation. The attack vector requires an attacker to control the content of a form’s option list; if such control is possible—e.g., via an API, form input, or database model—the attacker can supply malicious labels that are rendered unescaped. This leads to direct script execution in a visitor’s browser, potentially compromising the user experience and data integrity.
OpenCVE Enrichment