Skip to content

Escape validation messages in the PHP templating engine

Moderate
glye published GHSA-j35q-6w6m-9fpg Apr 21, 2022

Package

composer ibexa/templated-uri-bundle (Composer)

Affected versions

v2.1.*, v3.3.*

Patched versions

v2.1.0.1, v3.3.2.1

Description

This security advisory is about a vulnerability in Symfony where validation messages are not escaped, which can lead to XSS when user input is included. There is no known exploit against Ibexa software, but we recommend applying the fix.

The issue is fixed in symfony/framework-bundle 2.8.50, 3.4.26, 4.1.12, and 4.2.7.
The Ibexa package ibexa/templated-uri-bundle requires these versions since v2.1.0.1 (eZ Platform v2.5), and v3.3.2.1 (Ibexa DXP v3.3 and v4).

Severity

Moderate

CVE ID

No known CVE

Weaknesses

No CWEs