CVE-2019-11325

critical

Description

An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes strings, allowing some specially crafted ones to escalate to execution of arbitrary PHP code. This is related to symfony/var-exporter.

References

https://symfony.com/blog/symfony-4-3-8-released

https://symfony.com/blog/cve-2019-11325-fix-escaping-of-strings-in-varexporter

https://github.com/symfony/var-exporter/compare/d8bf442...57e00f3

https://github.com/symfony/symfony/releases/tag/v4.3.8

Details

Source: Mitre, NVD

Published: 2019-11-21

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical