CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
SINGLE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:S/C:P/I:P/A:P
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
EPSS
Percentile
31.0%
A potential Server-Side Template Injection vulnerability exists in Sprout Forms which could lead to the execution of Twig code.
The problem is fixed inbarrelstrength/sprout-forms:v3.9.0
which upgrades to barrelstrength/sprout-base-email:v1.2.7
Users unable to upgrade should update any Notification Emails to use the “Basic Notification (Sprout Email)” template and avoid using the “Basic Notification (Sprout Forms)” template or any custom templates that display Form Fields.
If you have any questions or comments about this advisory:
Vendor | Product | Version | CPE |
---|---|---|---|
barrelstrength | sprout-forms | * | cpe:2.3:a:barrelstrength:sprout-forms:*:*:*:*:*:*:*:* |
barrelstrength | sprout-base-email | * | cpe:2.3:a:barrelstrength:sprout-base-email:*:*:*:*:*:*:*:* |
github.com/advisories/GHSA-px8v-hxxx-2rgh
github.com/barrelstrength/craft-sprout-base-email/commit/5ef759f4713ede6dbf77c9d9df9f992876e43a49
github.com/barrelstrength/craft-sprout-forms/blob/v3/CHANGELOG.md#390---2020-04-09-critical
github.com/barrelstrength/craft-sprout-forms/security/advisories/GHSA-px8v-hxxx-2rgh
nvd.nist.gov/vuln/detail/CVE-2020-11056
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
SINGLE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:S/C:P/I:P/A:P
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
EPSS
Percentile
31.0%