CVE-2019-10910

CRITICAL

Symfony 2.7.0-2.7.50, 2.8.0-2.8.49, 3.0.0-3.4.25, 4.0.0-4.1.11, 4.2.0-4.2.6 - SQLi & RCE via Service ID

Title source: llm
STIX 2.1

Description

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection.

References (3)

Core 3

Scores

CVSS v3 9.8
EPSS 0.0549
EPSS Percentile 91.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (5)
drupal/drupal 8.5.0 - 8.5.15
sensiolabs/symfony 2.7.0 - 2.7.51
symfony/dependency-injection 2.7.0 - 2.7.51Packagist
symfony/proxy-manager-bridge 2.7.0 - 2.7.51Packagist
symfony/symfony 2.7.0 - 2.7.51Packagist
Published May 16, 2019
Tracked Since Feb 18, 2026