PT-2015-7622 · Sensio · Twig

Fabpot

·

Published

2015-08-26

·

Updated

2022-05-14

·

CVE-2015-7809

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sensio Labs Twig versions prior to 1.20.0
Description The issue allows remote attackers to execute arbitrary code via the self variable in a template when Sandbox mode is enabled. This is related to the displayBlock function in Template.php.
Recommendations For versions prior to 1.20.0, update to version 1.20.0 or later to resolve the issue. As a temporary workaround, consider disabling the displayBlock function or restricting the use of the self variable in templates until a patch is available. Restrict access to the Template.php file to minimize the risk of exploitation.

Exploit

Fix

RCE

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-7809
DSA-3343-1
GHSA-XW83-PWRM-9J74

Affected Products

Twig