S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2022-38467 Scanner

CVE-2022-38467 scanner - Cross Site Scripting vulnerability in CRM Perks Forms

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.3k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-38467
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

Reflected Cross-Site Scripting (XSS) vulnerability in CRM Perks Forms – WordPress Form Builder <= 1.1.0 ver.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
CRM Perks Forms – WordPress Form Builderby CRM Perks
n/a
Updated Aug 22, 2026View on NVD →
Detail

CRM Perks Forms is a WordPress plugin designed to create and manage forms for customer relationship management (CRM) purposes. It is used by businesses and website owners to gather information from site visitors, including contact details and feedback, which can be directly integrated into CRM systems. The plugin offers a user-friendly interface for form creation, customization, and data handling, facilitating efficient lead generation and customer interaction for WordPress sites.

The Cross-Site Scripting (XSS) vulnerability in CRM Perks Forms versions prior to 1.1.1 arises from the plugin's failure to properly sanitize and escape certain parameters in a sample file before outputting them back onto the page. This oversight allows attackers to inject malicious scripts into web pages, which are then executed in the browser of any user who views the affected page. Such vulnerabilities are a significant security risk, potentially leading to unauthorized access to user sessions and sensitive information.

Specifically, the vulnerability is located within the plugin's handling of parameters in the sample_file.php file. Attackers can exploit this by crafting URLs with malicious JavaScript code in the query parameters, targeting the FirstName, LastName, and Company fields. When a user accesses these URLs, the malicious script is executed, leading to various potential attacks including session hijacking, website defacement, and phishing attempts. The vulnerability highlights the critical importance of input validation and output encoding in web application security.

Exploiting this XSS vulnerability could lead to several adverse outcomes, such as theft of cookies, session tokens, or other sensitive information controlled by the browser. Attackers could also manipulate web page content or redirect users to malicious sites, compromising the integrity and reputation of the affected website. Such incidents can erode user trust and potentially result in regulatory scrutiny or legal consequences for the site owners.

S4E's platform provides comprehensive cybersecurity solutions, including the detection of vulnerabilities like XSS in CRM Perks Forms. By leveraging our services, users can benefit from detailed vulnerability assessments, expert remediation advice, and continuous monitoring to protect their digital assets. Joining S4E empowers website owners to proactively address security risks, ensuring the safety and reliability of their online presence.

 

References

Solution Advice
  1. Upgrade to CRM Perks Forms version 1.1.1 or later, which contains fixes for the XSS vulnerability.
  2. Implement content security policies (CSP) to mitigate the impact of XSS attacks.
  3. Regularly update all WordPress plugins and themes to their latest versions to address security vulnerabilities.
  4. Educate users about the risks of clicking on unknown links and the importance of using web browser security features.
  5. Conduct regular security audits of the website to identify and fix potential vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.