CVE-2020-11056

In Sprout Forms before 3.9.0, there is a potential Server-Side Template Injection vulnerability when using custom fields in Notification Emails which could lead to the execution of Twig code. This has been fixed in 3.9.0.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:barrelstrengthdesign:sprout_forms:*:*:*:*:*:*:*:*

Information

Published : 2020-05-07 14:15

Updated : 2021-10-26 13:00


NVD link : CVE-2020-11056

Mitre link : CVE-2020-11056


JSON object : View

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Advertisement

dedicated server usa

Products Affected

barrelstrengthdesign

  • sprout_forms