GHSA-72x2-5c85-6wmr

    Dashboard / Vulnerabilities / GHSA-72x2-5c85-6wmr

    GHSA-72x2-5c85-6wmr

    Published: 12 Nov 2023Last Modified: 10 Sept 2026

    Summary: Symfony potential Cross-site Scripting in WebhookController

    Details: ### Description The error message in WebhookController returns unescaped user-submitted input. ### Resolution WebhookController now doesn't return any user-submitted input in its response. The patch for this issue is available [here](https://github.com/symfony/symfony/commit/8128c302430394f639e818a7103b3f6815d8d962) for branch 6.3. ### Credits We would like to thank Maxime Aknin for reporting the issue and to Nicolas Grekas for providing the fix.

    Affected packages

    Package

    Name: symfony/webhook

    Purl: pkg:composer/symfony/webhook

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 6.3.0
    Fixed -6.3.8

    Affected versions

    v6.3.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-72x2-5c85-6wmr | CVE-DB