CyberSectr
Menü
← CVE Veritabanı

CVE-2026-76089

Yüksek

Teknik Veri (Otomatik)

CVSS Skoru
7.7
EPSS
—
CWE
CWE-200
KEV Durumu
Hayır

Formie, formlar oluşturmak için bir Craft CMS eklentisidir. 2.2.23 ve 3.1.31 sürümlerinden önceki sürümlerde, Formie'nin formie/sent-notifications/get-resend-modal-content kontrol paneli eylemi, SentNotificationsController::actionGetResendModalContent, bir izin veya nesne düzeyinde yetkilendirme kontrolleri olmadan bir bildirim Kimliği kabul eder. Eylemi çağırmaya yetkili olan herhangi bir kimlik doğrulama yapılmış kullanıcı, bildirim Kimliklerini sıralayabilir ve alıcı başlıkları ve gönderilen form verilerini içeren tam HTML e-posta gövdesini okuyabilir, hatta gönderilen bildirimleri görme izni olmasa bile. Bu sorun, 2.2.23 ve 3.1.31 sürümlerinde giderilmiştir.

Orijinal açıklama (İngilizce)

Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/sent-notifications/get-resend-modal-content control panel action in SentNotificationsController::actionGetResendModalContent accepts a request-supplied notification ID without permission or object-level authorization checks. Any authenticated user able to invoke the action can enumerate notification IDs and read recipient headers and complete HTML email bodies containing submitted form data, even without the sent-notification viewing permission. This issue is fixed in versions 2.2.23 and 3.1.31.

Bu CVE için henüz editoryal inceleme yapılmadı. Sadece otomatik teknik veri gösteriliyor.