symfony/lox24-notifier is vulnerable to Improper Authentication
65
Medium Risk
Symfony webhook parsers receive configured provider secrets but do not enforce the expected webhook authentication. A forged POST to an application webhook endpoint is decoded and accepted as a provider event. Pre-fix applications can process fake delivery, bounce, spam, click, or status events. The fix requires provider-specific credentials or tokens before accepting the webhook.
You are affected if you are using a version that falls within the vulnerable range.
symfony/lox24-notifier is vulnerable to Improper Authentication in versions 7.1.0 - 7.4.11 and 8.0.0 - 8.0.11.
Upgrade the symfony/lox24-notifier library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant