CVE-2019-10913Cross-site Scripting in Symfony

Severity
9.8CRITICALNVD
EPSS
0.3%
top 50.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 16
Latest updateDec 2

Description

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using the override header may be treated as trusted input, but they are not validated, possibly causing SQL injection or XSS. This is related to symfony/http-foundation.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

Packagistsymfony/http-foundation2.7.02.7.51+4
Packagistsymfony/symfony2.7.02.7.51+4
NVDsensiolabs/symfony2.7.02.7.51+4
Debiansymfony/symfony< 3.4.22+dfsg-2+3

Patches

🔴Vulnerability Details

4
OSV
Invalid HTTP method overrides allow possible XSS or other attacks in Symfony2019-12-02
GHSA
Invalid HTTP method overrides allow possible XSS or other attacks in Symfony2019-12-02
CVEList
CVE-2019-10913: In Symfony before 22019-05-16
OSV
CVE-2019-10913: In Symfony before 22019-05-16

📋Vendor Advisories

1
Debian
CVE-2019-10913: symfony - In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1...2019

💬Community

5
Bugzilla
CVE-2019-10909 CVE-2019-10910 CVE-2019-10912 CVE-2019-10913 CVE-2018-19790 CVE-2018-19789 php-symfony: Multiple vulnerabilities fixed in symfony 2.8.7 [epel-all]2019-06-12
Bugzilla
CVE-2019-10909 CVE-2019-10910 CVE-2019-10912 CVE-2019-10913 CVE-2018-19790 CVE-2018-19789 php-symfony: Multiple vulnerabilities fixed in symfony 2.8.72019-06-12
Bugzilla
CVE-2019-10909 CVE-2019-10910 CVE-2019-10912 CVE-2019-10913 CVE-2018-19790 CVE-2018-19789 php-symfony: Multiple vulnerabilities fixed in symfony 2.8.7 [fedora-all]2019-06-12
Bugzilla
CVE-2019-10909 CVE-2019-10910 CVE-2019-10912 CVE-2019-10913 CVE-2018-19790 CVE-2018-19789 php-symfony4: php-symfony: Multiple vulnerabilities fixed in symfony 2.8.7 [fedora-all]2019-06-12
Bugzilla
CVE-2019-10909 CVE-2019-10910 CVE-2019-10912 CVE-2019-10913 CVE-2018-19790 CVE-2018-19789 php-symfony3: php-symfony: Multiple vulnerabilities fixed in symfony 2.8.7 [fedora-all]2019-06-12
CVE-2019-10913 — Cross-site Scripting in Symfony | cvebase