CVE-2023-46735

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Nov 10, 2023
Updated: Nov 16, 2023
CWE ID 79

Summary

CVE-2023-46735 is a vulnerability in the Symfony PHP framework for web and console applications. The error message in WebhookController of Symfony versions 6.0.0 to 6.3.8 returns unescaped user-submitted input, which can lead to cross-site scripting (XSS) attacks. The vulnerability affects a wide range of products and components within the Symfony framework. To remediate the vulnerability, users should update to version 6.3.8 or later, where WebhookController no longer returns any user-submitted input in its response. The potential danger posed by this vulnerability is categorized as medium with a base severity score of 6.1 out of 10 according to NIST's CVSS scoring system, indicating a moderate level of risk.

Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2023-46735 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options