Description
An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes strings, allowing some specially crafted ones to escalate to execution of arbitrary PHP code. This is related to symfony/var-exporter.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-0317 | An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes strings, allowing some specially crafted ones to escalate to execution of arbitrary PHP code. This is related to symfony/var-exporter. |
Github GHSA |
GHSA-w4rc-rx25-8m86 | Improper Input Validation in Symfony |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T22:48:09.218Z
Reserved: 2019-04-18T00:00:00.000Z
Link: CVE-2019-11325
No data.
Status : Modified
Published: 2019-11-21T23:15:13.297
Modified: 2024-11-21T04:20:53.507
Link: CVE-2019-11325
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA