Vulnerabilities > CVE-2020-25912 - XXE vulnerability in Getsymphony Symphony 2.7.10
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
NONE Availability impact
HIGH Summary
A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS).
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |