The control panel action formie/integrations/form-settings (IntegrationsController::actionFormSettings) was reachable by any authenticated user without the appropriate form integration permissions. The action applied request-supplied settings to a fully configured integration via setAttributes($settings, false), allowing an attacker to overwrite outbound host properties (e.g. apiUrl) while the server sent stored API keys or OAuth tokens to the attacker-controlled host. The remote response was returned in the JSON body (non-blind SSRF).
This is an incomplete remediation of GHSA-cvpc-hccg-wmw4. The form-settings action was excluded from the permission gate added in 3.1.28.
Any site where a low-privileged user can authenticate (including front-end members on sites with public registration) could exfiltrate CRM/email-marketing/webhook integration credentials and probe internal network endpoints.
Fixed in 3.1.31 (Craft 5) and 2.2.23 (Craft 4).
The action now requires a CP request, a valid formId, and form integration permissions (formie-showFormIntegrations / per-form variant on Craft 5; formie-manageFormIntegrations / per-form variant on Craft 4). Request settings are filtered to an allowlist; URL, host, and credential properties cannot be overridden from user input.
Restrict front-end user registration and limit CP access until upgraded. No configuration-only workaround fully mitigates the issue.
{
"cwe_ids": [
"CWE-862",
"CWE-915",
"CWE-918"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-23T18:33:57Z",
"nvd_published_at": null,
"severity": "HIGH"
}