GHSA-px8v-hxxx-2rgh
Potential Code Injection in Sprout Forms
Quick fix
GHSA-px8v-hxxx-2rgh — barrelstrength/sprout-base-email: upgrade to the fixed version with the command below.
composer require barrelstrength/sprout-base-email:^1.2.7Details
### Impact
A potential Server-Side Template Injection vulnerability exists in Sprout Forms which could lead to the execution of Twig code.
### Patches
The problem is fixed in`barrelstrength/sprout-forms:v3.9.0` which upgrades to `barrelstrength/sprout-base-email:v1.2.7`
### Workarounds
Users unable to upgrade should update any Notification Emails to use the "Basic Notification (Sprout Email)" template and avoid using the "Basic Notification (Sprout Forms)" template or any custom templates that display Form Fields.
### References
- See the release notes in the [CHANGELOG](https://github.com/barrelstrength/craft-sprout-forms/blob/v3/CHANGELOG.md#390---2020-04-09-critical) - Credits to Paweł Hałdrzyński, Daniel Kalinowski from [ISEC.PL](https://isec.pl/) for discovery and responsible disclosure
### For more information
If you have any questions or comments about this advisory:
* Open an issue in the [Sprout Forms repo](https://github.com/barrelstrength/craft-sprout-forms/issues) * Email us at [sprout@barrelstrengthdesign.com](mailto:sprout@barrelstrengthdesign.com)
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 1.2.7composer require barrelstrength/sprout-base-email:^1.2.70Fixed in: 3.9.0composer require barrelstrength/sprout-forms:^3.9.0References
- https://github.com/barrelstrength/craft-sprout-forms/security/advisories/GHSA-px8v-hxxx-2rgh[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2020-11056[ADVISORY]
- https://github.com/barrelstrength/craft-sprout-base-email/commit/5ef759f4713ede6dbf77c9d9df9f992876e43a49[WEB]
- https://github.com/barrelstrength/craft-sprout-forms/blob/v3/CHANGELOG.md#390---2020-04-09-critical[WEB]