CVE-2018-13818
CRITICALSymfony Twig < 2.4.4 - Code Injection
Title source: ruleDescription
Twig before 2.4.4 allows Server-Side Template Injection (SSTI) via the search search_key parameter. NOTE: the vendor points out that Twig itself is not a web application and states that it is the responsibility of web applications using Twig to properly wrap input to it
Exploits (1)
References (5)
Scores
CVSS v3
9.8
EPSS
0.0054
EPSS Percentile
67.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-94
Status
published
Products (1)
symfony/twig
< 2.4.4
Published
Jul 10, 2018
Tracked Since
Feb 18, 2026