CVE-2024-45592 - "Symphony Auditor-Bundle Unescaped Entity Property JavaScript Injection"

CVE ID : CVE-2024-45592 Published : Sept. 10, 2024, 4:15 p.m. | 1 hour, 14 minutes ago Description : auditor-bundle, formerly known as DoctrineAuditBundle, integrates auditor library into any Symfony 3.4+ application. Prior to 6.0.0, there is an unescaped entity property enabling Javascript injection. This is possible because %source_label% in twig macro is not escaped. Therefore script tags can be inserted and are executed. The vulnerability is fixed in 6.0.0. Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Sep 10, 2024 - 19:30
 0  3
CVE-2024-45592 - "Symphony Auditor-Bundle Unescaped Entity Property JavaScript Injection"
CVE ID : CVE-2024-45592
Published : Sept. 10, 2024, 4:15 p.m. | 1 hour, 14 minutes ago
Description : auditor-bundle, formerly known as DoctrineAuditBundle, integrates auditor library into any Symfony 3.4+ application. Prior to 6.0.0, there is an unescaped entity property enabling Javascript injection. This is possible because %source_label% in twig macro is not escaped. Therefore script tags can be inserted and are executed. The vulnerability is fixed in 6.0.0.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...