← Back

CVE-2020-11056

nvd nist
Published: May 7, 2020Modified: Nov 21, 2024

JSON object

Loading...
6.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Exploitability: 2.8 / Impact: 3.4
Source: NVD

Description

In Sprout Forms before 3.9.0, there is a potential Server-Side Template Injection vulnerability when using custom fields in Notification Emails which could lead to the execution of Twig code. This has been fixed in 3.9.0.

Affected (1)

Sprout Forms
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.9.0

Timeline

No history available yet.