In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using the override header may be treated as trusted input, but they are not validated, possibly causing SQL injection or XSS. This is related to symfony/http-foundation.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSensiolabs Symfony
APPSensiolabs2.7.0 – 2.7.51 (excl.)2.8.0 – 2.8.50 (excl.)3.4.0 – 3.4.26 (excl.)4.1.0 – 4.1.12 (excl.)4.2.0 – 4.2.7 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLiXSS
Related vulnerabilities
CVE-2026-45063CRITICAL9.1PL ✓same product
Symfony X509Authenticator — obejście uwierzytelniania przez błędny regex DN
CVE-2019-18889CRITICAL9.8PL ✓same product
Symfony: zdalne wykonanie kodu przez serializację adaptera cache
CVE-2019-11325CRITICAL9.8PL ✓same product
Symfony VarExporter — nieprawidłowe escapowanie umożliwia RCE
CVE-2017-11365CRITICAL9.8PL ✓same product
Nieprawidłowa kontrola dostępu w komponencie Password validator — Symfony
CVE-2019-10910CRITICAL9.8PL ✓same product
SQL Injection i RCE w Symfony przez niezwalidowane identyfikatory serwisów