CVE-2024-35191
20.05.2024, 21:15
Formie is a Craft CMS plugin for creating forms. Prior to 2.1.6, users with access to a form's settings can include malicious Twig code into fields that support Twig. These might be the Submission Title or the Success Message. This code will then be executed upon creating a submission, or rendering the text. This has been fixed in Formie 2.1.6.Enginsight
Vendor | Product | Version |
---|---|---|
verbb | formie | 𝑥 < 2.0.44 |
verbb | formie | 2.1.0 ≤ 𝑥 < 2.1.6 |
𝑥
= Vulnerable software versions
References