Improper Neutralization of Server-Side Includes Within a Web Page Affecting verbb/formie package, versions <2.1.6
Threat Intelligence
EPSS
0.04% (10th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PHP-VERBBFORMIE-6928871
- published 21 May 2024
- disclosed 20 May 2024
- credit XCapri
Introduced: 20 May 2024
CVE-2024-35191 Open this link in a new tabHow to fix?
Upgrade verbb/formie
to version 2.1.6 or higher.
Overview
Affected versions of this package are vulnerable to Improper Neutralization of Server-Side Includes Within a Web Page in the form's settings. An attacker can execute arbitrary code by including malicious Twig code into fields that support Twig, such as the Submission Title or the Success Message.
References
CVSS Scores
version 3.1