Improper authorization control for web services In verbb/formie
Description
Formie: Missing authorization on sent notification resend modal exposes submission PII
Impact
The control panel action formie/sent-notifications/get-resend-modal-content (SentNotificationsController::actionGetResendModalContent) performed only requireAcceptsJson() and loaded a SentNotification by request id without permission or object-level authorization checks.
Any authenticated user who could invoke the action could enumerate notification IDs and read full email content — including recipient headers and the complete HTML body containing submitted form data (PII) — without formie-accessSentNotifications or equivalent permission. Sibling actions in the same controller enforced authorization.
Patches
Fixed in 3.1.31 (Craft 5) and 2.2.23 (Craft 4).
Craft 5: canView() is enforced after loading, consistent with actionEdit.
Craft 4: formie-viewSentNotifications permission is required.
Workarounds
Restrict CP access to trusted users only until upgraded. No configuration workaround.
Reported by Jorge González (jorge@jmilla.es)
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
packagist | 3.1.31, 2.2.23 |
Aliases
References