Process Maker pm4core-docker Cross-Site Scripting Vulnerability

Vulnerability

A cross-site scripting (XSS) vulnerability exists in Process Maker pm4core-docker version 4.1.21-RC7. This vulnerability allows attackers to execute arbitrary web scripts or HTML by injecting a crafted payload into the Name parameter. The issue arises from inadequate input sanitization in the import function, enabling the execution of malicious JavaScript when a processed file is archived.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user.

Reproduction

To reproduce this vulnerability, upload a JSON file containing an XSS payload through the process import feature. Once the file is imported, the malicious script will execute when the process is archived. Additionally, HTML files can be uploaded and will bypass image restrictions in the custom login logo section, although PHP files can be uploaded, they are not executed.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
7.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.