JhumanJ OpnForm Cross-Site Scripting Vulnerability in Form Editor

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in JhumanJ OpnForm versions through 1.9.3. The issue resides in the Form Editor component, specifically within the file '/api/open/forms/'. This vulnerability allows for remote exploitation, where an authenticated user can inject malicious JavaScript that is executed in the browsers of users or administrators viewing the form. This could lead to the theft of session cookies or bearer tokens, potentially allowing for account takeover. The vendor has temporarily disabled the feature until users configure their own domain, which will mitigate this vulnerability.

Impact

Exploitation of this vulnerability allows for authenticated stored cross-site scripting, where injected scripts are executed in the context of the user or administrator viewing the form. This could enable the theft of session cookies or bearer tokens, leading to account takeover.

Added: Oct 8, 2025, 6:18 AM
Updated: Oct 8, 2025, 6:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
6.3
remediation
0.0
relevance
0.7
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.