Directory Traversal Vulnerability in Symfony Intl Component
CVE-2017-16654
7.5HIGH
Summary
An issue has been identified in the Symfony framework that affects its Intl component prior to specified versions. This vulnerability arises from the way the read() methods handle user-provided locale arguments, allowing an attacker to perform directory traversal attacks. By manipulating these inputs, an attacker can access unauthorized directories on the server, leading to potential data exposure.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved