solspace/craft-freeform is vulnerable to Missing Authorization
43
Medium Risk
Two Control Panel API endpoints in Freeform return data without enforcing the corresponding Freeform permission. The asset card thumbnail endpoint exposes asset metadata such as IDs, titles, filenames, and URLs, and the notification template endpoint exposes template subjects, bodies, sender and reply-to details, and recipient addresses. Any signed-in Craft user with Control Panel access can read this data even without the forms-access or notifications-access permission, disclosing notification template contents and asset details. The fix adds the required permission checks to both endpoints before returning data.
You are affected if you are using a version that falls within the vulnerable range and you have Craft users with Control Panel access who lack the relevant Freeform permissions.
solspace/craft-freeform is vulnerable to Missing Authorization in versions 5.0.0 - 5.15.26.
Upgrade the solspace/craft-freeform library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.