Impact
The control panel action formie/integrations/form-settings (IntegrationsController::actionFormSettings) was reachable by any authenticated user without the appropriate form integration permissions. The action applied request-supplied settings to a fully configured integration via setAttributes($settings, false), allowing an attacker to overwrite outbound host properties (e.g. apiUrl) while the server sent stored API keys or OAuth tokens to the attacker-controlled host. The remote response was returned in the JSON body (non-blind SSRF).
This is an incomplete remediation of GHSA-cvpc-hccg-wmw4. The form-settings action was excluded from the permission gate added in 3.1.28.
Any site where a low-privileged user can authenticate (including front-end members on sites with public registration) could exfiltrate CRM/email-marketing/webhook integration credentials and probe internal network endpoints.
Patches
Fixed in 3.1.31 (Craft 5) and 2.2.23 (Craft 4).
The action now requires a CP request, a valid formId, and form integration permissions (formie-showFormIntegrations / per-form variant on Craft 5; formie-manageFormIntegrations / per-form variant on Craft 4). Request settings are filtered to an allowlist; URL, host, and credential properties cannot be overridden from user input.
Workarounds
Restrict front-end user registration and limit CP access until upgraded. No configuration-only workaround fully mitigates the issue.
References
Impact
The control panel action
formie/integrations/form-settings(IntegrationsController::actionFormSettings) was reachable by any authenticated user without the appropriate form integration permissions. The action applied request-supplied settings to a fully configured integration viasetAttributes($settings, false), allowing an attacker to overwrite outbound host properties (e.g.apiUrl) while the server sent stored API keys or OAuth tokens to the attacker-controlled host. The remote response was returned in the JSON body (non-blind SSRF).This is an incomplete remediation of GHSA-cvpc-hccg-wmw4. The
form-settingsaction was excluded from the permission gate added in 3.1.28.Any site where a low-privileged user can authenticate (including front-end members on sites with public registration) could exfiltrate CRM/email-marketing/webhook integration credentials and probe internal network endpoints.
Patches
Fixed in 3.1.31 (Craft 5) and 2.2.23 (Craft 4).
The action now requires a CP request, a valid
formId, and form integration permissions (formie-showFormIntegrations/ per-form variant on Craft 5;formie-manageFormIntegrations/ per-form variant on Craft 4). Request settings are filtered to an allowlist; URL, host, and credential properties cannot be overridden from user input.Workarounds
Restrict front-end user registration and limit CP access until upgraded. No configuration-only workaround fully mitigates the issue.
References