| Vulnerability Name: | CVE-2019-10909 (CCN-159637) | ||||||||||||||||||||||||||||||||||||
| Assigned: | 2019-04-17 | ||||||||||||||||||||||||||||||||||||
| Published: | 2019-04-17 | ||||||||||||||||||||||||||||||||||||
| Updated: | 2021-04-20 | ||||||||||||||||||||||||||||||||||||
| Summary: | In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. This is related to symfony/framework-bundle. | ||||||||||||||||||||||||||||||||||||
| CVSS v3 Severity: | 5.4 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N) 5.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)
5.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||
| CVSS v2 Severity: | 3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N)
| ||||||||||||||||||||||||||||||||||||
| Vulnerability Type: | CWE-79 | ||||||||||||||||||||||||||||||||||||
| Vulnerability Consequences: | Cross-Site Scripting | ||||||||||||||||||||||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2019-10909 Source: XF Type: UNKNOWN drupal-cve201910909-xss(159637) Source: CONFIRM Type: Patch, Third Party Advisory https://github.com/symfony/symfony/commit/ab4d05358c3d0dd1a36fc8c306829f68e3dd84e2 Source: CONFIRM Type: Vendor Advisory https://symfony.com/blog/cve-2019-10909-escape-validation-messages-in-the-php-templating-engine Source: CCN Type: SA-CORE-2019-005 Drupal core - Moderately critical - Multiple Vulnerabilities Source: MISC Type: Third Party Advisory https://www.drupal.org/sa-core-2019-005 Source: CCN Type: IBM Security Bulletin 882578 (API Connect) IBM API Connect's Developer Portal is impacted by vulnerabilities in Drupal core (CVE-2019-10909 CVE-2019-10910 CVE-2019-10911) Source: CONFIRM Type: Third Party Advisory https://www.synology.com/security/advisory/Synology_SA_19_19 | ||||||||||||||||||||||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||||||
| Oval Definitions | |||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||
| BACK | |||||||||||||||||||||||||||||||||||||