CVE-2019-10909
- EPSS 0.63%
- Veröffentlicht 16.05.2019 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:20:06
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. This is related to symfony/framework-bundle.
CVE-2018-19790
- EPSS 0.47%
- Veröffentlicht 18.12.2018 22:29:05
- Zuletzt bearbeitet 21.11.2024 03:58:33
An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9 and 4.2.x before 4.2.1. By using backslashes in the `_failure_path` input field of login forms, an attacke...
CVE-2018-19789
- EPSS 0.9%
- Veröffentlicht 18.12.2018 22:29:04
- Zuletzt bearbeitet 21.11.2024 03:58:33
An issue was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9, and 4.2.x before 4.2.1. When using the scalar type hint `string` in a setter method (e.g. `setName(string $name)`...
CVE-2017-16790
- EPSS 0.72%
- Veröffentlicht 06.08.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:16:58
An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. When a form is submitted by the user, the request handler classes of the Form component merge POST data and uploaded files data into one array. This b...
CVE-2017-16654
- EPSS 0.57%
- Veröffentlicht 06.08.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:16:46
An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The Intl component includes various bundle readers that are used to read resource bundles from the local filesystem. The read() methods of these class...
CVE-2017-16653
- EPSS 0.34%
- Veröffentlicht 06.08.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:16:46
An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The current implementation of CSRF protection in Symfony (Version >=2) does not use different tokens for HTTP and HTTPS; therefore the token is subjec...
CVE-2018-14774
- EPSS 0.1%
- Veröffentlicht 03.08.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:45
An issue was discovered in HttpKernel in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. When using HttpCache, the values of the X-Forwarded-Host headers a...
CVE-2018-14773
- EPSS 14.05%
- Veröffentlicht 03.08.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:45
An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. It arises from support for a (legacy) IIS header that lets us...
CVE-2017-18343
- EPSS 0.5%
- Veröffentlicht 20.07.2018 00:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:53
The debug handler in Symfony before v2.7.33, 2.8.x before v2.8.26, 3.x before v3.2.13, and 3.3.x before v3.3.6 has XSS via an array key during exception pretty printing in ExceptionHandler.php, as demonstrated by a /_debugbar/open?op=get URI. NOTE: t...
CVE-2018-12040
- EPSS 0.29%
- Veröffentlicht 13.06.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:44:28
Reflected Cross-site scripting (XSS) vulnerability in the web profiler in SensioLabs Symfony 3.3.6 allows remote attackers to inject arbitrary web script or HTML via the "file" parameter, aka an _profiler/open?file= URI. NOTE: The vendor states "The...