Symfony Cross-site Scripting (XSS) vulnerability
Moderate severity
GitHub Reviewed
Published
Nov 12, 2019
to the GitHub Advisory Database
•
Updated Feb 14, 2024
Package
Affected versions
>= 8.6.0, < 8.6.15
>= 8.0.0, < 8.5.15
Patched versions
8.6.15
8.5.15
>= 2.7.0, < 2.7.51
>= 2.8.0, < 2.8.50
>= 3.0.0, < 3.4.26
>= 4.0.0, < 4.1.12
>= 4.2.0, < 4.2.7
2.7.51
2.8.50
3.4.26
4.1.12
4.2.7
>= 2.7.0, < 2.7.51
>= 2.8.0, < 2.8.50
>= 3.0.0, < 3.4.26
>= 4.0.0, < 4.1.12
>= 4.2.0, < 4.2.7
2.7.51
2.8.50
3.4.26
4.1.12
4.2.7
Description
Published by the National Vulnerability Database
May 16, 2019
Reviewed
Nov 12, 2019
Published to the GitHub Advisory Database
Nov 12, 2019
Last updated
Feb 14, 2024
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. This is related to symfony/framework-bundle.
References