← Back to CVE List

CVE-2019-11325

Published: 2019-11-21T23:15Z
Last Modified: 2024-11-21T04:20Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes strings, allowing some specially crafted ones to escalate to execution of arbitrary PHP code. This is related to symfony/var-exporter. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt