GHSA-g996-q5r8-w7g2
Dashboard / Vulnerabilities / GHSA-g996-q5r8-w7g2
Summary: Symfony Cross-site Scripting (XSS) vulnerability
Details: In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. This is related to symfony/framework-bundle.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-10909, https://github.com/symfony/symfony/commit/ab4d05358c3d0dd1a36fc8c306829f68e3dd84e2, https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/core/CVE-2019-10909.yaml, https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/drupal/CVE-2019-10909.yaml, https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/framework-bundle/CVE-2019-10909.yaml, https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2019-10909.yaml, https://symfony.com/blog/cve-2019-10909-escape-validation-messages-in-the-php-templating-engine, https://symfony.com/cve-2019-10909, https://www.drupal.org/sa-core-2019-005, https://www.synology.com/security/advisory/Synology_SA_19_19
Affected packages
Package
Name: symfony/symfony
Purl: pkg:composer/symfony/symfony
Affected ranges
Type: ECOSYSTEM
Events:
