Formie: Missing authorization on sent notification resend modal exposes submission PII
🔗 CVE IDs covered (1)
📋 Description
Impact
The control panel action formie/sent-notifications/get-resend-modal-content (SentNotificationsController::actionGetResendModalContent) performed only requireAcceptsJson() and loaded a SentNotification by request id without permission or object-level authorization checks.
Any authenticated user who could invoke the action could enumerate notification IDs and read full email content — including recipient headers and the complete HTML body containing submitted form data (PII) — without formie-accessSentNotifications or equivalent permission. Sibling actions in the same controller enforced authorization.
Patches
Fixed in 3.1.31 (Craft 5) and 2.2.23 (Craft 4).
Craft 5: canView() is enforced after loading, consistent with actionEdit.
Craft 4: formie-viewSentNotifications permission is required.
Workarounds
Restrict CP access to trusted users only until upgraded. No configuration workaround.
- Reported by Jorge González ([email protected])
🎯 Affected products2
- composer/verbb/formie:>= 3.0.0, < 3.1.31
- composer/verbb/formie:< 2.2.23
🔗 References (6)
- https://github.com/verbb/formie/security/advisories/GHSA-9rg8-2wvr-fgjh
- https://github.com/verbb/formie/commit/9f4e23c36b907ed7677563231eaba373fdb8b84b
- https://github.com/verbb/formie/commit/ff81a895fa91a2e4efb8d4714501ba2d92df0b76
- https://github.com/verbb/formie/releases/tag/2.2.23
- https://github.com/verbb/formie/releases/tag/3.1.31
- https://github.com/advisories/GHSA-9rg8-2wvr-fgjh