PT-2023-10191 · Sumocoders · Sumocoders Frameworkuserbundle

Published

2023-01-03

·

Updated

2024-08-06

·

CVE-2015-10012

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions sumocoders FrameworkUserBundle versions up to 1.3.x
Description A vulnerability was found in sumocoders FrameworkUserBundle, affecting some unknown functionality of the file Resources/views/Security/login.html.twig. The manipulation leads to information exposure through error message.
Recommendations For sumocoders FrameworkUserBundle versions up to 1.3.x, upgrade to version 1.4.0 to address this issue.

Fix

Generation of Error Message Containing Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2015-10012
GHSA-6M7C-45FF-3328

Affected Products

Sumocoders Frameworkuserbundle