PT-2019-4599 · Symfony · Symfony

Michael Cullum

·

Publicado

2019-04-17

·

Atualizado

2021-04-20

·

CVE-2019-10909

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Symfony versions prior to 2.7.51 Symfony versions 2.8.x prior to 2.8.50 Symfony versions 3.x prior to 3.4.26 Symfony versions 4.x prior to 4.1.12 Symfony versions 4.2.x prior to 4.2.7
Description The issue is related to the lack of protection measures for web page structures in the symfony/framework-bundle of the Symfony platform, which can lead to XSS attacks when user input is included in validation messages. This can allow a remote attacker to perform an XSS attack.
Recommendations For Symfony versions prior to 2.7.51, update to version 2.7.51 or later. For Symfony versions 2.8.x prior to 2.8.50, update to version 2.8.50 or later. For Symfony versions 3.x prior to 3.4.26, update to version 3.4.26 or later. For Symfony versions 4.x prior to 4.1.12, update to version 4.1.12 or later. For Symfony versions 4.2.x prior to 4.2.7, update to version 4.2.7 or later.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-00699
CVE-2019-10909
DLA-1778-1
DSA-4441-1
GHSA-G996-Q5R8-W7G2

Produtos afetados

Symfony