PT-2020-12517 · Sprout · Sprout Forms

Daniel Kalinowski

+1

·

Published

2020-05-07

·

Updated

2021-10-26

·

CVE-2020-11056

CVSS v3.1

7.4

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Sprout Forms versions prior to 3.9.0
Description A potential Server-Side Template Injection issue exists in Sprout Forms, which could lead to the execution of Twig code when using custom fields in Notification Emails.
Recommendations For versions prior to 3.9.0, update to version 3.9.0 to fix the issue. As a temporary workaround for users unable to upgrade, update any Notification Emails to use the "Basic Notification (Sprout Email)" template and avoid using the "Basic Notification (Sprout Forms)" template or any custom templates that display Form Fields.

Fix

Code Injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-11056
GHSA-PX8V-HXXX-2RGH

Affected Products

Sprout Forms