verbb/formie is vulnerable to Missing Authorization
54
Medium Risk
The EmailController preview and test-send actions enforce no Formie permission and no control-panel access, so any authenticated Craft user, including a self-registered front-end account, can reach them. Both actions build a Notification entirely from request input with mass-assignment filtering disabled, letting the caller send email through the site mailer with a chosen recipient, from, subject and body, and render arbitrary notification content. Because notification fields are evaluated as Twig, the actions also expose sandboxed server-side template injection. The fix requires control-panel access and Formie permissions on both actions and restricts which notification attributes can be populated.
You are affected if you are using a version that falls within the vulnerable range and your site allows untrusted users to obtain an authenticated Craft session, such as self-registered front-end member accounts.
verbb/formie is vulnerable to Missing Authorization in versions 1.1.0 - 2.2.25 and 3.0.0 - 3.1.33.
Upgrade the verbb/formie library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant