CVE-2019-10909 PUBLISHED

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. This is related to symfony/framework-bundle.

EPSS 0.37% · 58.5th percentile

Risk Scores

EPSS Score
0.37%
58.5th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSsymfony3.4.6+dfsg-1ubuntu0.1+esm2, 0, 2.8.7+dfsg-1.3ubuntu1
Ubuntu:16.04:LTSsymfony2.7.1+dfsg-1, 2.7.5+dfsg-1, 2.7.9+dfsg-1

Timeline

References

Open in Interactive Console →