VDB
CVE-2019-10909
CVE-2019-10909
PUBLISHED
CVSS 5.400000095367432 MEDIUM
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. This is related to symfony/framework-bundle.
EPSS 1.03% · 62.3th percentile
Risk Scores
CVSS 3.1
5.400000095367432
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS Score
1.03%
62.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:Pro:18.04:LTS | symfony | 0, 2.8.7+dfsg-1.3ubuntu1, 3.4.3+dfsg-1ubuntu4 |
| Ubuntu:16.04:LTS | symfony | 0, 2.7.1+dfsg-1, 2.7.5+dfsg-1 |
Timeline
- Apr 17, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Oct 27, 2021 EPSS Score
- Dec 29, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 4, 2022 EPSS Score
- Jul 6, 2022 EPSS Score
- Sep 9, 2022 EPSS Score
- Jan 13, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2019-10909 third-party-advisory
- https://www.drupal.org/SA-CORE-2019-005 third-party-advisory
- https://symfony.com/blog/cve-2019-10909-escape-validation-messages-in-the-php-templating-engine third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2019-10909 third-party-advisory