Lack of data validation In twig/twig
Description
Twig remote code execution in templates
The displayBlock function Template.php in Sensio Labs Twig before 1.20.0, when Sandbox mode is enabled, allows remote attackers to execute arbitrary code via the _self variable in a template.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 1.20.0 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4. 5. 6. 7. 8.