HeyForm
- <= 3.0.0-rc.6
A stored cross-site scripting vulnerability has been identified in HeyForm, an open-source form builder, prior to version 3.0.0-rc.7. This vulnerability allows a low-privileged team member to inject malicious JavaScript into form field titles. The injected script executes when a team owner views the form, potentially leading to a complete account takeover by transferring team ownership to the attacker.
Exploitation of this vulnerability allows for stored cross-site scripting, which can be executed in the context of the user viewing the form. In multi-user teams, this could lead to a critical privilege escalation, allowing the attacker to become the team owner and gain full control over the workspace. For users on the SaaS platform heyform.net, this vulnerability could be exploited to take over another user's account.
To reproduce this vulnerability, a low-privileged team member can use the 'updateFormSchemas' GraphQL mutation to inject a malicious script into a form's title. Once the script is injected, it will execute when the form is viewed by a team owner. This can be verified by checking if the injected script was executed, such as by transferring team ownership to the attacker's account.
Users can update to HeyForm version 3.0.0-rc.7 or later, where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.