CVE-2019-11325

Published
View on NVD ↗
CVSS v3
9.8
CRITICAL
CVSS v2
7.5
HIGH
Affected
2
PROJECTS

Description

An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes strings, allowing some specially crafted ones to escalate to execution of arbitrary PHP code. This is related to symfony/var-exporter.

The Symfony PHP framework
GitHubGitHub
31.1K
Provides tools to export, instantiate, hydrate, clone and lazy-load PHP objects
GitHubGitHub
2.1K