Advisories

HeyForm Reflects Any Origin in CORS Responses While Allowing Credentials

Go Back
severity
high
date
Affecting
  • heyform >= 0, < 3.0.0-rc.8

CWE
  • CWE-942 Permissive Cross-domain Security Policy with Untrusted Domains
CVSS
8.1
Credit
George Chen
Description
HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing credentials, enabling cross-origin requests with authentication. Attackers can execute authenticated GraphQL queries from malicious pages visited by logged-in users to access workspaces, projects, forms, submissions, and respondent data, or modify account settings.

Ready to get Started?

Explore VulnCheck, a next-generation Cyber Threat Intelligence platform, which provides exploit and vulnerability intelligence to help you prioritize and remediate vulnerabilities that matter.
  • Vulnerability Prioritization
    Prioritize vulnerabilities that matter based on the threat landscape and defer vulnerabilities that don't.
  • Early Warning System
    Real-time alerting of changes in the vulnerability landscape so that you can take action before the attacks start.