CVE-2019-10909
Summary
| CVE | CVE-2019-10909 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-05-16 22:29:00 UTC |
| Updated | 2021-04-20 12:53:00 UTC |
| Description | In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. This is related to symfony/framework-bundle. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Drupal | Drupal | All | All | All | All |
| Application | Drupal | Drupal | All | All | All | All |
| Application | Sensiolabs | Symfony | All | All | All | All |
| Application | Sensiolabs | Symfony | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2019-10909: Escape validation messages in the PHP templating engine (Symfony Blog) | CONFIRM | symfony.com | Vendor Advisory |
| Synology Inc. | CONFIRM | www.synology.com | |
| Fix XSS issues in the form theme of the PHP templating engine · symfony/symfony@ab4d053 · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| Drupal core - Moderately critical - Multiple Vulnerabilities - SA-CORE-2019-005 | Drupal.org | MISC | www.drupal.org | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.