Lucene search

K
osvGoogleOSV:GHSA-X92H-WMG2-6HP7
HistoryDec 02, 2019 - 6:10 p.m.

Invalid HTTP method overrides allow possible XSS or other attacks in Symfony

2019-12-0218:10:24
Google
osv.dev
42

EPSS

0.002

Percentile

54.7%

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using the override header may be treated as trusted input, but they are not validated, possibly causing SQL injection or XSS. This is related to symfony/http-foundation.