CyberRota Analysis
AI-GeneratedThe Formie plugin for Craft CMS is vulnerable due to a lack of permission checks in the SentNotificationsController, allowing any authenticated user to access and enumerate notification IDs, revealing sensitive recipient information and complete HTML email bodies containing submitted form data. This poses a significant risk of data exposure for organizations using affected versions prior to 2.2.23 and 3.1.31. Users of the Formie plugin should prioritize updating to the latest versions to mitigate this high-severity vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/sent-notifications/get-resend-modal-content control panel action in SentNotificationsController::actionGetResendModalContent accepts a request-supplied notification ID without permission or object-level authorization checks. Any authenticated user able to invoke the action can enumerate notification IDs and read recipient headers and complete HTML email bodies containing submitted form data, even without the sent-notification viewing permission. This issue is fixed in versions 2.2.23 and 3.1.31.