CVE-2024-35191
published 2024-05-20CVE-2024-35191: Formie is a Craft CMS plugin for creating forms. Prior to 2.1.6, users with access to a form's settings can include malicious Twig code into fields that…
PriorityP419medium4.4CVSS 3.1
AVLACLPRHUINSUCHINAN
EPSS
0.26%
17.5th percentile
Formie is a Craft CMS plugin for creating forms. Prior to 2.1.6, users with access to a form's settings can include malicious Twig code into fields that support Twig. These might be the Submission Title or the Success Message. This code will then be executed upon creating a submission, or rendering the text. This has been fixed in Formie 2.1.6.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| verbb | formie | < 2.1.6 | 2.1.6 |
| verbb | formie | < 2.0.44 | 2.0.44 |
| verbb | formie | >= 0 < 2.1.6 | 2.1.6 |
| verbb | formie | >= 2.1.0 < 2.1.6 | 2.1.6 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
verbb/formie Server-Side Template Injection for variable-enabled settings
ghsa·2024-05-20
CVE-2024-35191 [MEDIUM] CWE-1336 verbb/formie Server-Side Template Injection for variable-enabled settings
verbb/formie Server-Side Template Injection for variable-enabled settings
### Impact
Users with access to a form's settings can include malicious Twig code into fields that support Twig. These might be the Submission Title or the Success Message. This code will then be executed upon creating a submission, or rendering the text.
This is listed as low-medium severity due to requiring control panel access to edit a form's settings.
### Patches
This has been fixed in Formie 2.1.6. Users should ensure they are running at least this version.
OSV
verbb/formie Server-Side Template Injection for variable-enabled settings
osv·2024-05-20
CVE-2024-35191 [MEDIUM] verbb/formie Server-Side Template Injection for variable-enabled settings
verbb/formie Server-Side Template Injection for variable-enabled settings
### Impact
Users with access to a form's settings can include malicious Twig code into fields that support Twig. These might be the Submission Title or the Success Message. This code will then be executed upon creating a submission, or rendering the text.
This is listed as low-medium severity due to requiring control panel access to edit a form's settings.
### Patches
This has been fixed in Formie 2.1.6. Users should ensure they are running at least this version.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/verbb/formie/commit/90296edf7e707f117e760aa57e70dbd43a854420https://github.com/verbb/formie/security/advisories/GHSA-v45m-hxqp-fwf5https://github.com/verbb/formie/commit/90296edf7e707f117e760aa57e70dbd43a854420https://github.com/verbb/formie/security/advisories/GHSA-v45m-hxqp-fwf5
2024-05-20
Published