6.8
CVSSv2

CVE-2015-7809

Published: 06/11/2015 Updated: 30/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The displayBlock function Template.php in Sensio Labs Twig prior to 1.20.0, when Sandbox mode is enabled, allows remote malicious users to execute arbitrary code via the _self variable in a template.

Vulnerable Product Search on Vulmon Subscribe to Product

symfony twig

Vendor Advisories

James Kettle, Alain Tiemblo, Christophe Coevoet and Fabien Potencier discovered that twig, a templating engine for PHP, did not correctly process its input End users allowed to submit twig templates could use specially crafted code to trigger remote code execution, even in sandboxed templates For the stable distribution (jessie), this problem has ...