CVE-2019-10912
- EPSS 1.16%
- Veröffentlicht 16.05.2019 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:20:08
In Symfony before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, it is possible to cache objects that may contain bad user input. On serialization or unserialization, this could result in the deletion of files that the current ...
CVE-2019-10910
- EPSS 12.5%
- Veröffentlicht 16.05.2019 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:20:07
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-inject...
CVE-2019-10909
- EPSS 0.38%
- Veröffentlicht 16.05.2019 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:20:06
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. This is related to symfony/framework-bundle.
CVE-2018-19790
- EPSS 0.45%
- Veröffentlicht 18.12.2018 22:29:05
- Zuletzt bearbeitet 21.11.2024 03:58:33
An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9 and 4.2.x before 4.2.1. By using backslashes in the `_failure_path` input field of login forms, an attacke...
CVE-2018-19789
- EPSS 0.87%
- Veröffentlicht 18.12.2018 22:29:04
- Zuletzt bearbeitet 21.11.2024 03:58:33
An issue was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9, and 4.2.x before 4.2.1. When using the scalar type hint `string` in a setter method (e.g. `setName(string $name)`...
CVE-2017-16790
- EPSS 0.72%
- Veröffentlicht 06.08.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:16:58
An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. When a form is submitted by the user, the request handler classes of the Form component merge POST data and uploaded files data into one array. This b...
CVE-2017-16654
- EPSS 0.57%
- Veröffentlicht 06.08.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:16:46
An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The Intl component includes various bundle readers that are used to read resource bundles from the local filesystem. The read() methods of these class...
CVE-2017-16653
- EPSS 0.34%
- Veröffentlicht 06.08.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:16:46
An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The current implementation of CSRF protection in Symfony (Version >=2) does not use different tokens for HTTP and HTTPS; therefore the token is subjec...
CVE-2018-14774
- EPSS 0.14%
- Veröffentlicht 03.08.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:45
An issue was discovered in HttpKernel in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. When using HttpCache, the values of the X-Forwarded-Host headers a...
CVE-2018-14773
- EPSS 16.65%
- Veröffentlicht 03.08.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:45
An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. It arises from support for a (legacy) IIS header that lets us...