Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. getformwork/formwork
  4. ›
  5. GHSA-c85w-x26q-ch87

GHSA-c85w-x26q-ch87: Formwork improperly validates input of User role preventing site and panel availability

March 1, 2025 (updated March 16, 2025)

Improper validation of select fields allows attackers to craft an input that crashes the system, resulting in a 500 status and making the entire site and administration panel unavailable. This clearly impacts the Availability aspect of the CIA triad (confidentiality, integrity, and availability), although the attack still has certain limitations.

References

  • github.com/advisories/GHSA-c85w-x26q-ch87
  • github.com/getformwork/formwork
  • github.com/getformwork/formwork/commit/d9f0c1feb3b9855d5bdc8bb189c0aaab2792e7ca
  • github.com/getformwork/formwork/security/advisories/GHSA-c85w-x26q-ch87

Code Behaviors & Features

Detect and mitigate GHSA-c85w-x26q-ch87 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 2.0.0-beta.1 before 2.0.0-beta.4

Fixed versions

  • 2.0.0-beta.4

Solution

Upgrade to version 2.0.0-beta.4 or above.

Impact 8.2 HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H

Learn more about CVSS

Weakness

  • CWE-1285: Improper Validation of Specified Index, Position, or Offset in Input
  • CWE-248: Uncaught Exception

Source file

packagist/getformwork/formwork/GHSA-c85w-x26q-ch87.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:00 +0000.