logo

Database

Server side template injection In verbb/formie

Description

verbb/formie Server-Side Template Injection for variable-enabled settings

Impact

Users with access to a form's settings can include malicious Twig code into fields that support Twig. These might be the Submission Title or the Success Message. This code will then be executed upon creating a submission, or rendering the text.

This is listed as low-medium severity due to requiring control panel access to edit a form's settings.

Patches

This has been fixed in Formie 2.1.6. Users should ensure they are running at least this version.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions
FLAT-IGY1P – Vulnerability | Fluid Attacks Database