CVE-2024-35191

MEDIUM4.4EPSS 0.22%

verbb/formie Server-Side Template Injection for variable-enabled settings

Published: 5/20/2024Modified: 5/20/2024
Also known as:GHSA-v45m-hxqp-fwf5

Description

### Impact Users with access to a form's settings can include malicious Twig code into fields that support Twig. These might be the Submission Title or the Success Message. This code will then be executed upon creating a submission, or rendering the text. This is listed as low-medium severity due to requiring control panel access to edit a form's settings. ### Patches This has been fixed in Formie 2.1.6. Users should ensure they are running at least this version.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM4.4CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

References (4)