Users with access to a form's settings can include malicious Twig code into fields that support Twig. These might be the Submission Title or the Success Message. This code will then be executed upon creating a submission, or rendering the text.
This is listed as low-medium severity due to requiring control panel access to edit a form's settings.
This has been fixed in Formie 2.1.6. Users should ensure they are running at least this version.
{
"github_reviewed": true,
"github_reviewed_at": "2024-05-20T20:26:28Z",
"nvd_published_at": "2024-05-20T21:15:09Z",
"cwe_ids": [
"CWE-1336"
],
"severity": "MODERATE"
}