CVE-2021-38143
6.1 MEDIUMAn issue was discovered in Form Tools through 3.0.20
Published: 2021-08-31 · Last updated: 2026-06-17
Severity and scoring
- CVSS
- 6.1 MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- CWE
- CWE-79
Affected products
| Vendor | Product |
|---|---|
| formtools | core |
Description
An issue was discovered in Form Tools through 3.0.20. When an administrator creates a customer account, it is possible for the customer to log in and proceed with a change of name and last name. However, these fields are vulnerable to XSS payload insertion, being triggered in the admin panel when the admin tries to see the client list. This type of XSS (stored) can lead to the extraction of the PHPSESSID cookie belonging to the admin.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2021-38143
- [Exploit reference]https://bernardofsr.github.io/blog/2021/form-tools/
- [Exploit reference]https://github.com/bernardofsr/CVEs-With-PoC/blob/main/PoCs/Form%20Tools/README.md
- [Other]https://github.com/formtools/core
- [Vendor advisory]https://www.formtools.org/
- [Exploit reference]https://bernardofsr.github.io/blog/2021/form-tools/
- [Exploit reference]https://github.com/bernardofsr/CVEs-With-PoC/blob/main/PoCs/Form%20Tools/README.md
- [Other]https://github.com/formtools/core
- [Vendor advisory]https://www.formtools.org/
Related CVEs
Same vendor
- CVE-2021-38145 — An issue was discovered in Form Tools through 3.0.20 (9.8 CRITICAL)
- CVE-2021-38144 — An issue was discovered in Form Tools through 3.0.20 (5.4 MEDIUM)
Same CWE
- CVE-2026-12425 — Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PowerSchool Employee Access ...
- CVE-2024-30476 — PowerStore contains a Stored Cross-Site Scripting Vulnerability in the PowerStore Manager (5.4 MEDIUM)
- CVE-2026-54198 — Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.35 versions (7.1 HIGH)
- CVE-2026-54191 — Unauthenticated Cross Site Scripting (XSS) in Pods <= 3.3.8 versions (7.1 HIGH)
- CVE-2026-39437 — Unauthenticated Cross Site Scripting (XSS) in Min Max Step Quantity Limits Manager for WooCommerce <= 5.2.2 versions (7.1 HIGH)