Lucene search

K
githubGitHub Advisory DatabaseGHSA-PX8V-HXXX-2RGH
HistoryMay 08, 2020 - 9:00 p.m.

Potential Code Injection in Sprout Forms

2020-05-0821:00:02
CWE-74
CWE-94
GitHub Advisory Database
github.com
145

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

EPSS

0.001

Percentile

31.0%

Impact

A potential Server-Side Template Injection vulnerability exists in Sprout Forms which could lead to the execution of Twig code.

Patches

The problem is fixed inbarrelstrength/sprout-forms:v3.9.0 which upgrades to barrelstrength/sprout-base-email:v1.2.7

Workarounds

Users unable to upgrade should update any Notification Emails to use the “Basic Notification (Sprout Email)” template and avoid using the “Basic Notification (Sprout Forms)” template or any custom templates that display Form Fields.

References

  • See the release notes in the CHANGELOG
  • Credits to Paweł Hałdrzyński, Daniel Kalinowski from ISEC.PL for discovery and responsible disclosure

For more information

If you have any questions or comments about this advisory:

Affected configurations

Vulners
Node
barrelstrengthsprout-formsRange<3.9.0
OR
barrelstrengthsprout-base-emailRange<1.2.7
VendorProductVersionCPE
barrelstrengthsprout-forms*cpe:2.3:a:barrelstrength:sprout-forms:*:*:*:*:*:*:*:*
barrelstrengthsprout-base-email*cpe:2.3:a:barrelstrength:sprout-base-email:*:*:*:*:*:*:*:*

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

EPSS

0.001

Percentile

31.0%

Related for GHSA-PX8V-HXXX-2RGH