In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using the override header may be treated as trusted input, but they are not validated, possibly causing SQL injection or XSS. This is related to symfony/http-foundation.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1778-1 | symfony security update |
Debian DSA |
DSA-4441-1 | symfony security update |
EUVD |
EUVD-2019-0806 | In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using the override header may be treated as trusted input, but they are not validated, possibly causing SQL injection or XSS. This is related to symfony/http-foundation. |
Github GHSA |
GHSA-x92h-wmg2-6hp7 | Invalid HTTP method overrides allow possible XSS or other attacks in Symfony |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T22:40:15.080Z
Reserved: 2019-04-07T00:00:00
Link: CVE-2019-10913
No data.
Status : Modified
Published: 2019-05-16T22:29:00.673
Modified: 2024-11-21T04:20:08.240
Link: CVE-2019-10913
No data.
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Github GHSA