8.5
CVE-2026-76086
- EPSS 0.29%
- Veröffentlicht 23.09.2026 18:32:37
- Zuletzt bearbeitet 30.09.2026 19:57:08
- Erkennungen
Formie: Integration form-settings action allows SSRF and exfiltration of stored integration credentials
Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/integrations/form-settings control panel action in IntegrationsController::actionFormSettings is reachable without the required form integration permissions and passes request-supplied settings to a configured integration. An authenticated attacker can replace outbound host properties such as apiUrl while the server uses stored API keys or OAuth tokens, causing non-blind server-side requests to an attacker-controlled or internal host and returning the remote response. This residual flaw remained because the permission gate added in version 3.1.28 excluded the form-settings action. Sites that permit low-privileged or front-end user authentication can therefore expose integration credentials and internal network responses. This issue is fixed in versions 2.2.23 and 3.1.31.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerverbb
≫
Produkt
formie
Version
< 2.2.23
Status
affected
Version
>= 3.0.0, < 3.1.31
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.29% | 0.193 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 8.5 | 3.1 | 4.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes
The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.
CWE-918 Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
https://github.com/verbb/formie/security/advisories/GHSA-v3f3-cmj4-cvj9
https://github.com/verbb/formie/commit/6735fe4ae8f6a2a76930716ad7876b236f7c530d
https://github.com/verbb/formie/commit/dde7799dfa7e4d0a11e28754ad8544dba62d5def
https://github.com/advisories/GHSA-cvpc-hccg-wmw4
https://github.com/verbb/formie/releases/tag/2.2.23
https://github.com/verbb/formie/releases/tag/3.1.31