CVE-2026-85484: fallo de gravedad media en HTML-FormHandler
HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping
Publicada el · Actualizada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 6.1epss 0.3%
probabilidad de explotación
0.3%top 76% de las CVE
explotación observada
noninguna fuente lo reporta
HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping.
The Select, RadioGroup, CheckboxGroup and HorizCheckboxGroup widgets render a group label unescaped, Select into a label attribute and the other three into element content. RadioGroup also renders each radio button's own label unescaped.
Any application whose option list is built from data rather than literals, using options_from, an options_fieldname method, or the DBIC model, allows attacker-influenced text in a label that can override the options or embed JavaScript in rendered pages.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Productos afectados
HTML-FormHandlerCVEs relacionadas — HTML-FormHandler
En el mismo producto, de las más peligrosas a las menos.
CVE-2022-4993CRITICALHTML::FormHandler versions before 0.410000 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation templateEPSS 0.6%CVE-2026-85485MEDIUMHTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escapingEPSS 0.3%CVE-2026-19872MEDIUMHTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error messageEPSS 0.3%CVE-2026-85630MEDIUMHTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs methodEPSS 0.2%