Users with access to a form's settings can include malicious Twig code into fields that support Twig. These might be the Submission Title or the Success Message. This code will then be executed upon creating a submission, or rendering the text.
This is listed as low-medium severity due to requiring control panel access to edit a form's settings.
This has been fixed in Formie 2.1.6. Users should ensure they are running at least this version.
{ "nvd_published_at": "2024-05-20T21:15:09Z", "cwe_ids": [ "CWE-1336" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-05-20T20:26:28Z" }