VulnerabilityModified
CVE-2019-10909
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included.
MEDIUM 5.4EPSS 1.03%
Does this matter?
Lower severity and a low EPSS score (1.03%). Track it; it rarely justifies an emergency change on its own.
Description
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. This is related to symfony/framework-bundle.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.03% probability · 62th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- sensiolabs/symfony · drupal/drupal
- Source
- cve@mitre.org
References
- https://github.com/symfony/symfony/commit/ab4d05358c3d0dd1a36fc8c306829f68e3dd84e2Patch, Third Party Advisory
- https://symfony.com/blog/cve-2019-10909-escape-validation-messages-in-the-php-templating-engineVendor Advisory
- https://www.drupal.org/sa-core-2019-005Third Party Advisory
- https://www.synology.com/security/advisory/Synology_SA_19_19Third Party Advisory
- https://github.com/symfony/symfony/commit/ab4d05358c3d0dd1a36fc8c306829f68e3dd84e2Patch, Third Party Advisory
- https://symfony.com/blog/cve-2019-10909-escape-validation-messages-in-the-php-templating-engineVendor Advisory
- https://www.drupal.org/sa-core-2019-005Third Party Advisory
- https://www.synology.com/security/advisory/Synology_SA_19_19Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.