CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
Percentile
82.6%
An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8.
The VarExport component incorrectly escapes strings, allowing some
specially crafted ones to escalate to execution of arbitrary PHP code. This
is related to symfony/var-exporter.
github.com/symfony/symfony/commit/0524868cbf3d3a36e0af804432016d5a6d98169a
launchpad.net/bugs/cve/CVE-2019-11325
nvd.nist.gov/vuln/detail/CVE-2019-11325
security-tracker.debian.org/tracker/CVE-2019-11325
symfony.com/blog/cve-2019-11325-fix-escaping-of-strings-in-varexporter
www.cve.org/CVERecord?id=CVE-2019-11325
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
Percentile
82.6%