CVE-2019-10909Cross-site Scripting in Symfony

CWE-79Cross-site Scripting13 documents7 sources
Severity
5.4MEDIUMNVD
EPSS
0.4%
top 42.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 16
Latest updateNov 12

Description

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. This is related to symfony/framework-bundle.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages7 packages

Packagistsymfony/framework-bundle2.7.02.7.51+4
Packagistsymfony/symfony2.7.02.7.51+4
NVDsensiolabs/symfony2.7.02.7.51+4
Debiansymfony/symfony< 3.4.22+dfsg-2+3
Packagistdrupal/core8.0.08.5.15+1

Patches

🔴Vulnerability Details

5
OSV
Symfony Cross-site Scripting (XSS) vulnerability2019-11-12
GHSA
Symfony Cross-site Scripting (XSS) vulnerability2019-11-12
CVEList
CVE-2019-10909: In Symfony before 22019-05-16
OSV
CVE-2019-10909: In Symfony before 22019-05-16
OSV
CVE-2019-10909: This security release fixes third-party dependencies included in or required by Drupal core2019-04-17

📋Vendor Advisories

2
Drupal
Drupal core - Moderately critical - Multiple Vulnerabilities - SA-CORE-2019-0052019-04-17
Debian
CVE-2019-10909: symfony - In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1...2019

💬Community

5
Bugzilla
CVE-2019-10909 CVE-2019-10910 CVE-2019-10912 CVE-2019-10913 CVE-2018-19790 CVE-2018-19789 php-symfony: Multiple vulnerabilities fixed in symfony 2.8.7 [epel-all]2019-06-12
Bugzilla
CVE-2019-10909 CVE-2019-10910 CVE-2019-10912 CVE-2019-10913 CVE-2018-19790 CVE-2018-19789 php-symfony: Multiple vulnerabilities fixed in symfony 2.8.72019-06-12
Bugzilla
CVE-2019-10909 CVE-2019-10910 CVE-2019-10912 CVE-2019-10913 CVE-2018-19790 CVE-2018-19789 php-symfony: Multiple vulnerabilities fixed in symfony 2.8.7 [fedora-all]2019-06-12
Bugzilla
CVE-2019-10909 CVE-2019-10910 CVE-2019-10912 CVE-2019-10913 CVE-2018-19790 CVE-2018-19789 php-symfony4: php-symfony: Multiple vulnerabilities fixed in symfony 2.8.7 [fedora-all]2019-06-12
Bugzilla
CVE-2019-10909 CVE-2019-10910 CVE-2019-10912 CVE-2019-10913 CVE-2018-19790 CVE-2018-19789 php-symfony3: php-symfony: Multiple vulnerabilities fixed in symfony 2.8.7 [fedora-all]2019-06-12
CVE-2019-10909 — Cross-site Scripting in Symfony | cvebase