Symfony 2.0.X before 2.0.24, 2.1.X before 2.1.12, 2.2.X before 2.2.5, and 2.3.X before 2.3.3 have an issue in the HttpFoundation component. The Host header can be manipulated by an attacker when the framework is generating an absolute URL. A remote attacker could exploit this vulnerability to inject malicious content into the Web application page and conduct various attacks.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2020-01-02 17:15
Updated : 2020-01-10 19:25
NVD link : CVE-2013-4752
Mitre link : CVE-2013-4752
CVE.ORG link : CVE-2013-4752
JSON object : View
Products Affected
fedoraproject
- fedora
sensiolabs
- symfony
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')