Описание
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. This is related to symfony/framework-bundle.
Релиз | Статус | Примечание |
---|---|---|
bionic | DNE | |
cosmic | DNE | |
devel | DNE | |
disco | DNE | |
eoan | DNE | |
esm-apps/xenial | not-affected | |
esm-infra-legacy/trusty | not-affected | |
esm-infra/focal | DNE | |
focal | DNE | |
groovy | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | ignored | end of standard support, was needed |
cosmic | ignored | end of life |
devel | not-affected | 3.4.22+dfsg-2ubuntu1 |
disco | ignored | end of life |
eoan | not-affected | 3.4.22+dfsg-2ubuntu1 |
esm-apps/bionic | needed | |
esm-apps/focal | not-affected | 3.4.22+dfsg-2ubuntu1 |
esm-apps/jammy | not-affected | 3.4.22+dfsg-2ubuntu1 |
esm-apps/noble | not-affected | 3.4.22+dfsg-2ubuntu1 |
esm-apps/xenial | needed |
Показывать по
3.5 Low
CVSS2
5.4 Medium
CVSS3
Связанные уязвимости
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. This is related to symfony/framework-bundle.
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x ...
Symfony Cross-site Scripting (XSS) vulnerability
Уязвимость функции проверки сообщения в symfony/framework-bundle программной платформы для разработки и управления веб-приложениями Symfony, связанная с отсутствием мер по защите структур веб-страницы, позволяющая нарушителю произвести XSS-атаку
3.5 Low
CVSS2
5.4 Medium
CVSS3