Intel

AIKIDO-2024-10186

verbb/formie is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

15

Low Risk

This Affects:

phpverbb/formie
1.2.0 - 2.1.20
Fixed in 2.1.21

TL;DR

Affected versions of the package are vulnerable to a Cross-site Scripting (XSS) vulnerability in sub-fields and sent email notifications.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

verbb/formie is vulnerable to Cross-site Scripting (XSS) in versions 1.2.0 - 2.1.20.

How to fix this

Upgrade the verbb/formie library to the patch version.