Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:4609
HistoryJul 19, 2017 - 10:37 p.m.

Arbitrary Code Execution

2017-07-1922:37:00
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

EPSS

0.072

Percentile

94.1%

twig is vulnerable to arbitrary code execution. Attackers can execute code by leveraging a flaw in the displayBlock function in Template.php through the _self variable. This can only be exploited when Sandbox mode is enabled.