Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:8048
HistoryDec 19, 2018 - 6:03 a.m.

Information Disclosure

2018-12-1906:03:31
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

0.011 Low

EPSS

Percentile

84.4%

symfony is vulnerable to information disclosure. Calling the UploadedFile::__toString() function discloses the path of the uploaded file, which can escalate to a remote code execution when used with a local file inclusion.