GHSA-2qrj-g9hq-chph
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Quick fix
GHSA-2qrj-g9hq-chph — Umbraco.Forms: upgrade to the fixed version with the command below.
dotnet add package Umbraco.Forms --version 13.4.2Details
### Impact The 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems).
### Patches This issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2.
### Workarounds Unpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or [writing a custom workflow type](https://docs.umbraco.com/umbraco-forms/developer/extending/adding-a-workflowtype).
To avoid accidentally using the vulnerable workflow again, the `SendEmail` workflow type can be removed using the following composer (tested on Umbraco 10, 13, 14 and 15): ```c# using Umbraco.Cms.Core.Composing; using Umbraco.Forms.Core.Providers.Extensions; using Umbraco.Forms.Core.Providers.WorkflowTypes;
internal sealed class RemoveFormsSendEmailWorkflowTypeComposer : IComposer { public void Compose(IUmbracoBuilder builder) => builder.FormsWorkflows().Exclude<SendEmail>(); } ```
Are you affected?
Enter the version of the package you're using.
Affected packages
7.0.0Fixed in: 13.4.2dotnet add package Umbraco.Forms --version 13.4.27.0.0No fixed version published yet for UmbracoForms (nuget). Pin to a known-safe version or switch to an alternative.
14.0.0Fixed in: 15.1.2dotnet add package Umbraco.Forms --version 15.1.2