icon

We found results for “

WS-2022-0059

Good to know:

icon

Date: January 29, 2022

In symfony the application sensible to CSRF attacks before versions 5.3.15,5.4.4 and 6.0.4.

Language: PHP

Severity Score

Severity Score

Weakness Type (CWE)

Cross-Site Request Forgery (CSRF)

CWE-352

Top Fix

icon

Upgrade Version

Upgrade to version symfony/framework-bundle - 5.4.x-dev;symfony/framework-bundle - v5.4.3;symfony/framework-bundle - v5.3.10;symfony/framework-bundle - v5.3.4;symfony/framework-bundle - v6.0.0-BETA3;symfony/framework-bundle - v6.0.0;linhecheng/cmlphp - 6.0.x-dev;linhecheng/cmlphp - 5.3.x-dev;linhecheng/cmlphp - v5.4.4;linhecheng/cmlphp - v5.3.15;linhecheng/cmlphp - v6.0.4;linhecheng/cmlphp - 5.4.x-dev;symfony/symfony - 5.3.x-dev;symfony/symfony - 6.0.x-dev;symfony/symfony - 5.4.x-dev;symfony/symfony - v5.4.4;symfony/symfony - v5.3.15;symfony/symfony - v6.0.4;symfony/symfony - vPR6;cybernodev/framework-bundle - no_fix;ics/userhelp-bundle - 0.0.3;kematjaya/crawling-processor-bundle - 1.1

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): REQUIRED
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): HIGH
Availability (A): NONE

Do you need more information?

Contact Us