VDB
Sign up
—0.0

GHSA-2qrj-g9hq-chph

Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow

Quick fix

GHSA-2qrj-g9hq-chph — Umbraco.Forms: upgrade to the fixed version with the command below.

dotnet add package Umbraco.Forms --version 13.4.2

Details

### Impact The 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address (potentially bypassing spam and email client security systems).

### Patches This issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2.

### Workarounds Unpatched or unsupported versions can workaround this issue by using the 'Send email with template (Razor)' workflow instead or [writing a custom workflow type](https://docs.umbraco.com/umbraco-forms/developer/extending/adding-a-workflowtype).

To avoid accidentally using the vulnerable workflow again, the `SendEmail` workflow type can be removed using the following composer (tested on Umbraco 10, 13, 14 and 15): ```c# using Umbraco.Cms.Core.Composing; using Umbraco.Forms.Core.Providers.Extensions; using Umbraco.Forms.Core.Providers.WorkflowTypes;

internal sealed class RemoveFormsSendEmailWorkflowTypeComposer : IComposer { public void Compose(IUmbracoBuilder builder) => builder.FormsWorkflows().Exclude<SendEmail>(); } ```

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/Umbraco.Forms
Introduced in: 7.0.0Fixed in: 13.4.2
Fixdotnet add package Umbraco.Forms --version 13.4.2
NuGet/UmbracoForms
Introduced in: 7.0.0

No fixed version published yet for UmbracoForms (nuget). Pin to a known-safe version or switch to an alternative.

NuGet/Umbraco.Forms
Introduced in: 14.0.0Fixed in: 15.1.2
Fixdotnet add package Umbraco.Forms --version 15.1.2

References