CVE-2018-9920: k2 Smartforms
Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.
Server side request forgery exists in the runtime application in K2 smartforms 4.6.11 via a modified hostname in an https://*/Identity/STS/Forms/Scripts URL.
Affected products
- k2 Smartforms: version 4.6.11 only
Published 2018-05-24. Last modified 2026-06-17.