CVE-2020-11056

Source
https://nvd.nist.gov/vuln/detail/CVE-2020-11056
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-11056.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-11056
Aliases
Published
2020-05-07T21:15:11Z
Modified
2024-05-14T07:31:50.323752Z
Severity
  • 6.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
[none]
Details

In Sprout Forms before 3.9.0, there is a potential Server-Side Template Injection vulnerability when using custom fields in Notification Emails which could lead to the execution of Twig code. This has been fixed in 3.9.0.

References

Affected packages

Git / github.com/barrelstrength/craft-sprout-forms

Affected ranges

Type
GIT
Repo
https://github.com/barrelstrength/craft-sprout-forms
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*

v0.7.1
v0.8.1
v0.8.2
v0.8.3
v0.8.4
v0.8.6
v0.8.7
v0.9.1

v1.*

v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.1.0

v2.*

v2.1.0
v2.4.0
v2.5.0
v2.5.1

v3.*

v3.0.0
v3.0.0-beta.1
v3.0.0-beta.10
v3.0.0-beta.12
v3.0.0-beta.13
v3.0.0-beta.14
v3.0.0-beta.15
v3.0.0-beta.16
v3.0.0-beta.17
v3.0.0-beta.18
v3.0.0-beta.2
v3.0.0-beta.20
v3.0.0-beta.21
v3.0.0-beta.22
v3.0.0-beta.24
v3.0.0-beta.25
v3.0.0-beta.26
v3.0.0-beta.27
v3.0.0-beta.28
v3.0.0-beta.29
v3.0.0-beta.3
v3.0.0-beta.30
v3.0.0-beta.31
v3.0.0-beta.32
v3.0.0-beta.33
v3.0.0-beta.34
v3.0.0-beta.35
v3.0.0-beta.36
v3.0.0-beta.37
v3.0.0-beta.38
v3.0.0-beta.39
v3.0.0-beta.4
v3.0.0-beta.40
v3.0.0-beta.41
v3.0.0-beta.42
v3.0.0-beta.43
v3.0.0-beta.44
v3.0.0-beta.45
v3.0.0-beta.46
v3.0.0-beta.47
v3.0.0-beta.48
v3.0.0-beta.49
v3.0.0-beta.5
v3.0.0-beta.50
v3.0.0-beta.51
v3.0.0-beta.52
v3.0.0-beta.53
v3.0.0-beta.54
v3.0.0-beta.55
v3.0.0-beta.56
v3.0.0-beta.57
v3.0.0-beta.6
v3.0.0-beta.7
v3.0.0-beta.8
v3.0.0-beta.9
v3.0.1
v3.0.2
v3.1.0
v3.2.0
v3.2.1
v3.2.2
v3.2.3
v3.2.4
v3.3.0
v3.3.1
v3.3.2
v3.3.3
v3.3.4
v3.3.5
v3.3.6
v3.3.7
v3.3.9
v3.4.0
v3.4.1
v3.4.2
v3.4.3
v3.5.0
v3.5.1
v3.6.0
v3.6.1
v3.6.10
v3.6.2
v3.6.4
v3.6.5
v3.6.6
v3.6.7
v3.6.8
v3.6.9
v3.7.0
v3.7.1
v3.7.1.1
v3.8.0
v3.8.0.1
v3.8.0.2
v3.8.1
v3.8.2
v3.8.3
v3.8.4
v3.8.5
v3.8.6
v3.8.7
v3.8.8