CVE-2024-51736

NONE

Symphony <5.4.45, <6.4.13, <7.1.6 - Command Injection

Title source: llm
STIX 2.1

Description

Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. On Windows, when an executable file named `cmd.exe` is located in the current working directory it will be called by the `Process` class when preparing command arguments, leading to possible hijacking. This issue has been addressed in release versions 5.4.46, 6.4.14, and 7.1.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.

References (1)

Core 1
Core References

Scores

CVSS v3 0.0
EPSS 0.0043
EPSS Percentile 34.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-77
Status published
Products (3)
sensiolabs/symfony < 5.4.46
symfony/process 0 - 5.4.46Packagist
symfony/symfony 0 - 5.4.46Packagist
Published Nov 06, 2024
Tracked Since Feb 18, 2026