Medium severity4.8NVD Advisory· Published Jun 29, 2020· Updated Jun 17, 2026
CVE-2020-13423
CVE-2020-13423
Description
Form Builder 2.1.0 for Magento has multiple XSS issues that can be exploited against Magento 2 admin accounts via the Current_url or email field, or the User-Agent HTTP header.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Magento/Form Builderdescription
- Range: = 2.1.0
- cpe:2.3:a:form_builder_for_magento_2_project:form_builder_for_magento_2:2.1.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- anothernetsecblog.com/magento-2-extension-security/nvdExploitThird Party AdvisoryURL Repurposed
- anothernetsecblog.comnvdThird Party AdvisoryURL Repurposed
- landofcoder.com/magento-2-form-builder.htmlnvdProductThird Party Advisory
News mentions
0No linked articles in our index yet.