We found results for “”
CVE-2023-37473
Date: July 14, 2023
zenstruck/collections is a set of helpers for iterating/paginating/filtering collections. Passing callable strings (ie "system") caused the function to be executed. This would result in a limited subset of specific user input being executed as if it were code. This issue has been addressed in commit "f4b1c48820" and included in release version 0.2.1. Users are advised to upgrade. Users unable to upgrade should ensure that user input is not passed to either "EntityRepository::find()" or "query()".
Language: PHP
Severity Score
Related Resources (6)
Severity Score
Weakness Type (CWE)
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CWE-74CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | HIGH |
| Privileges Required (PR): | LOW |
| User Interaction (UI): | NONE |
| Scope (S): | CHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | HIGH |
| Availability (A): | HIGH |
Vulnerabilities
Projects
Contact Us


