An issue was discovered in Terminalfour 7.4 through 7.4.0004 QP3 and 8 through 8.3.19, and Formbank through 2.1.10-FINAL. Unauthenticated Stored Cross-Site Scripting can occur, with resultant Admin Session Hijacking. The attack vectors are Form Builder and Form Preview.
| Software | From | Fixed in |
|---|---|---|
| terminalfour / terminalfour | 7.4.0004-qp3 | 7.4.0004-qp3.x |
| terminalfour / formbank | - | 2.1.10.x |
| terminalfour / terminalfour | 7.4 | 7.4.0004 |
| terminalfour / terminalfour | 8.0.0 | 8.3.19.x |
| terminalfour / terminalfour | 7.4.0004-qp2 | 7.4.0004-qp2.x |