CVE-2019-10910

CRITICAL

Sensiolabs Symfony < 2.7.51 - SQL Injection

Title source: rule
STIX 2.1

Description

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection.

References (3)

Core 3

Scores

CVSS v3 9.8
EPSS 0.1190
EPSS Percentile 93.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (5)
drupal/drupal 8.5.0 - 8.5.15
sensiolabs/symfony 2.7.0 - 2.7.51
symfony/dependency-injection 2.7.0 - 2.7.51Packagist
symfony/proxy-manager-bridge 2.7.0 - 2.7.51Packagist
symfony/symfony 2.7.0 - 2.7.51Packagist
Published May 16, 2019
Tracked Since Feb 18, 2026