Page 4 of 31 results (0.003 seconds)
CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 3

CVE-2018-12040 – SensioLabs Symfony 3.3.6 Cross Site Scripting
https://notcve.org/view.php?id=CVE-2018-12040
09 Jun 2018 — Reflected Cross-site scripting (XSS) vulnerability in the web profiler in SensioLabs Symfony 3.3.6 allows remote attackers to inject arbitrary web script or HTML via the "file" parameter, aka an _profiler/open?file= URI. NOTE: The vendor states "The XSS ... is in the web profiler, a tool that should never be deployed in production (so, we don't handle those issues as security issues). ** EN DISPUTA ** Vulnerabilidad de Cross-Site Scripting (XSS) reflejado en el generador de perfiles web en Symfony 3.3.6, de... • https://packetstorm.news/files/id/148125 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •