CVE-2024-37156 | SuluFormBundle up to 2.5.2 GET Parameter TokenController formName cross site scripting (GHSA-rrvc-c7xg-7cf3)
A vulnerability was found in SuluFormBundle up to 2.5.2. It has been rated as problematic. Affected by this issue is the function TokenController of the component GET Parameter Handler. The manipulation of the argument formName leads to basic cross site scripting.
This vulnerability is handled as CVE-2024-37156. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.