CVE-2026-107856
Beschrijving NL
CiviForm vereenvoudigt aanvragen voor uitkeringsprogramma's van de overheid door sollicitatiegegevens te hergebruiken voor meerdere uitkeringsprogramma's. Voorafgaand aan 3.33.0 controleert GET /admin/tiDash/editClientForm/:accountId of de aanvrager een vertrouwde tussenpersoon is, maar showEditClientForm voert een ruwe lookupAccount (accountId) uit zonder te bevestigen dat het burgeraccount tot de vertrouwde intermediaire groep van de aanvrager behoort. Een geverifieerde vertrouwde tussenpersoon kan accountId-waarden opsommen en de weergavenaam van de aanvrager lezen, inclusief de naam en het e-mailadres van de burger, voor accounts buiten de groep van de tussenpersoon. Dit probleem is opgelost in versie 3.33.0.
Origineel (Engels) tonen
CiviForm simplifies applications for government benefits programs by reusing applicant data across multiple benefit applications. Prior to 3.33.0, GET /admin/tiDash/editClientForm/:accountId verifies that the requester is a Trusted Intermediary but showEditClientForm performs a raw lookupAccount(accountId) without confirming that the citizen account belongs to the requester's trustedIntermediaryGroup. An authenticated Trusted Intermediary can enumerate accountId values and read the applicant display name, including the citizen's name and email address, for accounts outside the intermediary's group. This issue is fixed in version 3.33.0.