CVE-2024-45592

HIGH

Damienharper Auditor-bundle < 5.2.6 - XSS

Title source: rule
STIX 2.1

Description

auditor-bundle, formerly known as DoctrineAuditBundle, integrates auditor library into any Symfony 3.4+ application. Prior to version 5.2.6, there is an unescaped entity property enabling Javascript injection. This is possible because `%source_label%` in twig macro is not escaped. Therefore script tags can be inserted and are executed. The vulnerability is fixed in versions 6.0.0 and 5.2.6.

Scores

CVSS v3 8.2
EPSS 0.0036
EPSS Percentile 57.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (2)
damienharper/auditor-bundle 0 - 5.2.6Packagist
damienharper/auditor-bundle 5.0.0 - 5.2.6
Published Sep 10, 2024
Tracked Since Feb 18, 2026