PT-2023-27912 · Symfony · Symfony/Ux-Autocomplete

Janklan

·

Publicado

2023-09-11

·

Atualizado

2023-09-15

·

CVE-2023-41336

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions symfony/ux-autocomplete versions prior to 2.11.2
Description The issue allows an attacker to submit an entity id for an EntityType that is not part of the valid choices under certain circumstances. This can occur in applications that use a custom query builder option to limit valid results and an EntityType with 'autocomplete' => true or a custom AsEntityAutocompleteField. If an id is submitted, it is accepted even if the matching record would not be returned by the custom query built with query builder.
Recommendations For versions prior to 2.11.2, upgrade to version 2.11.2 or greater of symfony/ux-autocomplete to fix the issue. Alternatively, perform extra validation after submit to verify the selected option is valid.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-41336
GHSA-4CPV-669C-R79X

Produtos afetados

Symfony/Ux-Autocomplete