CVE-2015-10012 – sumocoders/framework-user-bundle
Package
Manager: composer
Name: sumocoders/framework-user-bundle
Vulnerable Version: >=0 <1.4.0
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00097 pctl0.27912
Details
FrameworkUserBundle Generates Error Message Containing Sensitive Information A vulnerability was found in sumocoders FrameworkUserBundle up to 1.3.x. It has been rated as problematic. Affected by this issue is some unknown functionality of the file `Resources/views/Security/login.html.twig`. The manipulation leads to information exposure through error message. Upgrading to version 1.4.0 can address this issue. The name of the patch is abe4993390ba9bd7821ab12678270556645f94c8. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-217268. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Metadata
Created: 2023-01-03T09:30:25Z
Modified: 2024-03-01T14:26:40Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-6m7c-45ff-3328/GHSA-6m7c-45ff-3328.json
CWE IDs: ["CWE-209"]
Alternative ID: GHSA-6m7c-45ff-3328
Finding: F037
Auto approve: 1