PT-2019-4599 · Symfony · Symfony
Michael Cullum
·
Published
2019-04-17
·
Updated
2021-04-20
·
CVE-2019-10909
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Symfony versions prior to 2.7.51
Symfony versions 2.8.x prior to 2.8.50
Symfony versions 3.x prior to 3.4.26
Symfony versions 4.x prior to 4.1.12
Symfony versions 4.2.x prior to 4.2.7
Description
The issue is related to the lack of protection measures for web page structures in the symfony/framework-bundle of the Symfony platform, which can lead to XSS attacks when user input is included in validation messages. This can allow a remote attacker to perform an XSS attack.
Recommendations
For Symfony versions prior to 2.7.51, update to version 2.7.51 or later.
For Symfony versions 2.8.x prior to 2.8.50, update to version 2.8.50 or later.
For Symfony versions 3.x prior to 3.4.26, update to version 3.4.26 or later.
For Symfony versions 4.x prior to 4.1.12, update to version 4.1.12 or later.
For Symfony versions 4.2.x prior to 4.2.7, update to version 4.2.7 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Symfony