CVE-2018-9920: k2 Smartforms

Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.

Server side request forgery exists in the runtime application in K2 smartforms 4.6.11 via a modified hostname in an https://*/Identity/STS/Forms/Scripts URL.

Affected products

  • k2 Smartforms: version 4.6.11 only

Published 2018-05-24. Last modified 2026-06-17.