logo

Database

Server-side request forgery (SSRF) In drupal/webform

Description

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.

The module includes a Webform Submission Export/Import submodule that allows importing submission data from uploaded CSV files or remote URLs.

The submodule did not sufficiently validate access to export/import functionality. A user who could edit webform submissions and access webform results could also access the import interface, including the remote URL import path, leading to a server-side request forgery vulnerability.

Sites that do not enable the Webform Submission Export/Import submodule are not affected.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions
FLAT-LJJBC – Vulnerability | Fluid Attacks Database