Impact
The module fails to escape some error messages that are rendered directly into HTML. When an attacker supplies input that causes an error, the error string can contain malicious JavaScript which is then injected into the page. This cross‑site scripting flaw allows an attacker to execute arbitrary client‑side code in the context of the site, potentially leading to session hijacking, credential theft, or defacement.
Affected Systems
The vulnerability affects the Perl distribution HTML::FormHandler. All versions older than 0.410002 are compromised on any system that uses the Table form layout, or the Bootstrap 2 or Bootstrap 3 wrappers. Any deployment that relies on these layouts for form rendering must verify its module version and upgrade if necessary.
Risk and Exploitability
The CVSS score is 6.1, and the EPSS score is <1%, indicating a moderate severity and low exploitation probability. The flaw is not listed in the CISA KEV catalog. The likely attack vector is a publicly accessible web form that uses the affected form layout; an attacker needs only to provide malicious input that triggers an error message. The unescaped error output would then be sent to the victim’s browser, enabling XSS. The exploit requires no special privileges beyond the ability to submit the form and view the resulting page.
OpenCVE Enrichment