symfony/web-profiler-bundle is vulnerable to Cross-site Scripting (XSS)
39
Low Risk
CodeExtension::fileExcerpt() escapes PHP files through syntax highlighting but renders non-PHP file lines without escaping. If attacker-controlled content is written to a file later viewed through a profiler excerpt, it can execute as HTML or JavaScript. Pre-fix development profiler views can expose stored XSS to developers. The fix escapes non-PHP file contents before rendering excerpts.
You are affected if you are using a version that falls within the vulnerable range.
symfony/web-profiler-bundle is vulnerable to Cross-site Scripting (XSS) in versions 7.2.9 - 7.4.11 and 8.0.0 - 8.0.11.
Upgrade the symfony/web-profiler-bundle and/or symfony/symfony library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant