CVE-2024-35191

CVSS V2 None CVSS V3 None
Description
Formie is a Craft CMS plugin for creating forms. Prior to 2.1.6, users with access to a form's settings can include malicious Twig code into fields that support Twig. These might be the Submission Title or the Success Message. This code will then be executed upon creating a submission, or rendering the text. This has been fixed in Formie 2.1.6.
Overview
  • CVE ID
  • CVE-2024-35191
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-05-20T20:26:24.492Z
  • Last Modified Date
  • 2024-06-06T19:18:34.888Z
History
Created Old Value New Value Data Type Notes
2024-06-26 13:39:09 Added to TrackCVE