Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in version 6.0.0 and prior to version 6.3.8, the error message in `WebhookController` returns unescaped user-submitted input. As of version 6.3.8, `WebhookController` now doesn't return any user-submitted input in its response.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2023-2904 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in version 6.0.0 and prior to version 6.3.8, the error message in `WebhookController` returns unescaped user-submitted input. As of version 6.3.8, `WebhookController` now doesn't return any user-submitted input in its response. |
![]() |
GHSA-72x2-5c85-6wmr | Symfony potential Cross-site Scripting in WebhookController |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-09-03T15:24:36.945Z
Reserved: 2023-10-25T14:30:33.752Z
Link: CVE-2023-46735

Updated: 2024-08-02T20:53:21.541Z

Status : Modified
Published: 2023-11-10T18:15:09.657
Modified: 2024-11-21T08:29:11.517
Link: CVE-2023-46735

No data.

No data.