CVE-2015-7809 Information
Feb 14, 2021
cve
Description
The displayBlock function Template.php in Sensio Labs Twig before 1.20.0 when Sandbox mode is enabled allows remote attackers to execute arbitrary code via the _self variable in a template.
Reference
http://openwall.com/lists/oss-security/2015/08/21/3 http://openwall.com/lists/oss-security/2015/10/11/2 http://symfony.com/blog/security-release-twig-1-20-0 http://www.debian.org/security/2015/dsa-3343 https://github.com/fabpot/Twig/commit/30be07759a3de2558da5224f127d052ecf492e8f https://github.com/twigphp/Twig/pull/1759
Share on: