CVE-2020-11056
Published
CVSS v3
7.4
HIGH
CVSS v2
6.5
MEDIUM
Affected
1
PROJECT
Description
In Sprout Forms before 3.9.0, there is a potential Server-Side Template Injection vulnerability when using custom fields in Notification Emails which could lead to the execution of Twig code. This has been fixed in 3.9.0.