CVE-2020-15143
Summary
| CVE | CVE-2020-15143 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-08-20 01:17:00 UTC |
| Updated | 2021-11-18 18:33:00 UTC |
| Description | In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, rrequest parameters injected inside an expression evaluated by `symfony/expression-language` package haven't been sanitized properly. This allows the attacker to access any public service by manipulating that request parameter, allowing for Remote Code Execution. This issue has been patched for versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4. Versions prior to 1.3 were not patched. |
Risk And Classification
Problem Types: CWE-917
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sylius | Syliusresourcebundle | All | All | All | All |
| Application | Sylius | Syliusresourcebundle | All | All | All | All |
| Application | Sylius | Syliusresourcebundle | All | All | All | All |
| Application | Sylius | Syliusresourcebundle | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Remote Code Execution in ParametersParser while using request parameters inside expression language · Advisory · Sylius/SyliusResourceBundle · GitHub | CONFIRM | github.com | Exploit, Mitigation, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.