CVE-2020-25912

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
31/10/2021
Last modified:
02/11/2021

Description

A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:getsymphony:symphony:2.7.10:*:*:*:*:*:*:*