CVE-2020-11056

Published
View on NVD ↗
CVSS v3
7.4
HIGH
CVSS v2
6.5
MEDIUM
Affected
1
PROJECT

Description

In Sprout Forms before 3.9.0, there is a potential Server-Side Template Injection vulnerability when using custom fields in Notification Emails which could lead to the execution of Twig code. This has been fixed in 3.9.0.

Simple, Beautiful Forms. 100% Control.
GitHubGitHub
18