icon

We found results for “

CVE-2023-37473

Date: July 14, 2023

zenstruck/collections is a set of helpers for iterating/paginating/filtering collections. Passing callable strings (ie "system") caused the function to be executed. This would result in a limited subset of specific user input being executed as if it were code. This issue has been addressed in commit "f4b1c48820" and included in release version 0.2.1. Users are advised to upgrade. Users unable to upgrade should ensure that user input is not passed to either "EntityRepository::find()" or "query()".

Language: PHP

Severity Score

Severity Score

Weakness Type (CWE)

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-74

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): HIGH
Privileges Required (PR): LOW
User Interaction (UI): NONE
Scope (S): CHANGED
Confidentiality (C): HIGH
Integrity (I): HIGH
Availability (A): HIGH

Do you need more information?

Contact Us