Impact
HTML::FormHandler versions prior to 0.410002 render field attributes into HTML using the process_attrs method without escaping. Any attribute value that is constructed from user input or variable data, rather than hard‑coded literals, can inject arbitrary text into an attribute value. This flaw enables an attacker to override default field attributes or insert JavaScript code into rendered pages, giving the attacker the ability to execute script in the victim’s browser context.
Affected Systems
The vulnerability exists in the Perl module HTML::FormHandler before version 0.410002. Applications that employ this module to generate form elements—particularly widgets such as RadioGroup that invoke process_attrs through render_option and wrap_radio—are affected. No vendor or product version list is provided beyond the module’s internal version numbering.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate severity for this reflected XSS flaw. Based on the description, it is inferred that the vulnerability is triggered when an attacker can influence attribute values, and because it is a server‑side rendering issue, the attacker does not need to compromise the server; a crafted request that includes malicious attribute data could trigger the flaw. The EPSS score of < 1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KE no known public exploits. However, the lack of escaping means that the risk remains significant for exposed web applications that rely on dynamic attribute construction.
OpenCVE Enrichment