Potential Code Injection in Sprout Forms
Critical severity
GitHub Reviewed
Published
May 4, 2020
in
barrelstrength/sprout-forms
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
May 7, 2020
Reviewed
May 8, 2020
Published to the GitHub Advisory Database
May 8, 2020
Last updated
Feb 1, 2023
Impact
A potential Server-Side Template Injection vulnerability exists in Sprout Forms which could lead to the execution of Twig code.
Patches
The problem is fixed in
barrelstrength/sprout-forms:v3.9.0
which upgrades tobarrelstrength/sprout-base-email:v1.2.7
Workarounds
Users unable to upgrade should update any Notification Emails to use the "Basic Notification (Sprout Email)" template and avoid using the "Basic Notification (Sprout Forms)" template or any custom templates that display Form Fields.
References
For more information
If you have any questions or comments about this advisory:
References