← Back

CVE-2023-46734

nvd nist
Published: Nov 10, 2023Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and prior to versions 4.4.51, 5.4.31, and 6.3.8, some Twig filters in CodeExtension use `is_safe=html` but don't actually ensure their input is safe. As of versions 4.4.51, 5.4.31, and 6.3.8, Symfony now escapes the output of the affected filters.

Affected (6)

Products: Sensiolabs: Symfony, Twig
2 products
Symfony
Twig
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Sensiolabs
From 2.0.0 to 4.4.51
From 5.0.0 to 5.4.31
From 6.0.0 to 6.3.8
Sensiolabs
From 2.0.0 to 4.4.51
From 5.0.0 to 5.4.31
From 6.0.0 to 6.3.8

Timeline

No history available yet.