Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v45m-hxqp-fwf5

Опубликовано: 20 мая 2024
Источник: github
Github: Прошло ревью
CVSS3: 4.4

Описание

verbb/formie Server-Side Template Injection for variable-enabled settings

Impact

Users with access to a form's settings can include malicious Twig code into fields that support Twig. These might be the Submission Title or the Success Message. This code will then be executed upon creating a submission, or rendering the text.

This is listed as low-medium severity due to requiring control panel access to edit a form's settings.

Patches

This has been fixed in Formie 2.1.6. Users should ensure they are running at least this version.

Пакеты

Наименование

verbb/formie

composer
Затронутые версииВерсия исправления

< 2.1.6

2.1.6

EPSS

Процентиль: 44%
0.00218
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-1336

Связанные уязвимости

CVSS3: 4.4
nvd
больше 1 года назад

Formie is a Craft CMS plugin for creating forms. Prior to 2.1.6, users with access to a form's settings can include malicious Twig code into fields that support Twig. These might be the Submission Title or the Success Message. This code will then be executed upon creating a submission, or rendering the text. This has been fixed in Formie 2.1.6.

EPSS

Процентиль: 44%
0.00218
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-1336