Symfony Web Profiler Cross Site Request Forgery Vulnerability
BID:70104
Info
Symfony Web Profiler Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 70104 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-6072 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 03 2014 12:00AM |
| Updated: | Sep 03 2014 12:00AM |
| Credit: | Damien Cauquil and Andreas Forsblom |
| Vulnerable: |
Symfony Symfony 2.5.2 Symfony Symfony 2.5.1 Symfony Symfony 2.4.8 Symfony Symfony 2.4.7 Symfony Symfony 2.3.18 Symfony Symfony 2.3.17 |
| Not Vulnerable: |
Symfony Symfony 2.5.4 Symfony Symfony 2.4.9 Symfony Symfony 2.3.19 |
Discussion
Symfony Web Profiler Cross Site Request Forgery Vulnerability
Symfony is prone to a cross-site request-forgery vulnerability.
An attacker can exploit the cross-site request forgery issue to perform unauthorized actions in the context of a logged-in user of the affected application. This may aid in other attacks.
Symfony is prone to a cross-site request-forgery vulnerability.
An attacker can exploit the cross-site request forgery issue to perform unauthorized actions in the context of a logged-in user of the affected application. This may aid in other attacks.
Exploit / POC
Symfony Web Profiler Cross Site Request Forgery Vulnerability
To exploit this issue an attacker must entice an unsuspecting victim to open a malicious URI.
To exploit this issue an attacker must entice an unsuspecting victim to open a malicious URI.
References
Symfony Web Profiler Cross Site Request Forgery Vulnerability
References:
References:
- CVE-2014-6072: CSRF vulnerability in the Web Profiler (Symfony )
- Symfony Homepage (Symfony)