PT-2021-11203 · Symphony · Symphony

Dahua966

·

Published

2021-10-31

·

Updated

2021-11-02

·

CVE-2020-25912

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Symphony version 2.7.10
Description: A XML External Entity (XXE) vulnerability was discovered in symphonylibtoolkitclass.xmlelement.php which can lead to an information disclosure or denial of service (DOS).
Recommendations: For Symphony version 2.7.10, consider disabling the class.xmlelement.php file in the symphonylibtoolkit directory as a temporary workaround until a patch is available. Restrict access to the vulnerable class.xmlelement.php file to minimize the risk of exploitation.

Exploit

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-25912

Affected Products

Symphony