logo

Database

Improper authorization control for web services In verbb/formie

Description

Formie: Missing authorization on sent notification resend modal exposes submission PII

Impact

The control panel action formie/sent-notifications/get-resend-modal-content (SentNotificationsController::actionGetResendModalContent) performed only requireAcceptsJson() and loaded a SentNotification by request id without permission or object-level authorization checks.

Any authenticated user who could invoke the action could enumerate notification IDs and read full email content — including recipient headers and the complete HTML body containing submitted form data (PII) — without formie-accessSentNotifications or equivalent permission. Sibling actions in the same controller enforced authorization.

Patches

Fixed in 3.1.31 (Craft 5) and 2.2.23 (Craft 4).

Craft 5: canView() is enforced after loading, consistent with actionEdit.
Craft 4: formie-viewSentNotifications permission is required.

Workarounds

Restrict CP access to trusted users only until upgraded. No configuration workaround.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions