CyberRota Analysis
AI-GeneratedA cross-site scripting vulnerability exists in the Form Write View component of TDuckApp tduck-platform versions up to 5.3, allowing remote attackers to manipulate the submitShowCustomPageContent argument. This flaw could lead to unauthorized script execution in the context of the user's session. Organizations using affected versions should prioritize remediation to mitigate potential exploitation risks.
Original NVD Description
A flaw has been found in TDuckApp tduck-platform up to 5.3. Affected by this vulnerability is an unknown functionality of the file tduck-front/src/views/form/write/index.vue of the component Form Write View. This manipulation of the argument submitShowCustomPageContent causes cross site scripting. The attack is possible to be carried out remotely. The project was informed of the problem early through an issue report but has not responded yet.