Описание
ux-autocomplete is a JavaScript Autocomplete functionality for Symfony. Under certain circumstances, an attacker could successfully submit an entity id for an EntityType that is not part of the valid choices. The problem has been fixed in symfony/ux-autocomplete version 2.11.2.
Ссылки
- Third Party Advisory
- Patch
- Vendor Advisory
- Product
- Third Party Advisory
- Patch
- Vendor Advisory
- Product
Уязвимые конфигурации
Конфигурация 1Версия до 2.11.2 (исключая)
cpe:2.3:a:symfony:ux_autocomplete:*:*:*:*:*:*:*:*
EPSS
Процентиль: 77%
0.01045
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-20
Связанные уязвимости
CVSS3: 6.5
github
больше 2 лет назад
Prevent injection of invalid entity ids for "autocomplete" fields
EPSS
Процентиль: 77%
0.01045
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-20