← Back

CVE-2015-7809

nvd nist
Published: Nov 6, 2015Modified: May 6, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

The displayBlock function Template.php in Sensio Labs Twig before 1.20.0, when Sandbox mode is enabled, allows remote attackers to execute arbitrary code via the _self variable in a template.

Affected (1)

Products: Symfony: Twig
1 product
Twig
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.19.0

Related CWEs

References (12)

Timeline

No history available yet.