PT-2018-10962 · Sensiolabs · Symfony

Published

2018-06-13

·

Updated

2024-08-05

·

CVE-2018-12040

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SensioLabs Symfony version 3.3.6
Description A reflected Cross-site scripting (XSS) issue exists in the web profiler, allowing remote attackers to inject arbitrary web script or HTML via the file parameter in an profiler/open?file= URI. The vendor notes that the web profiler should not be deployed in production.
Recommendations For SensioLabs Symfony version 3.3.6, consider disabling the web profiler to mitigate the risk of exploitation. Restrict access to the profiler/open?file= API endpoint to minimize the risk of arbitrary web script or HTML injection via the file parameter.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2018-12040

Affected Products

Symfony