#VU18299 Insecure deserialization in Symfony - CVE-2019-10912
Published: April 18, 2019
Symfony
SensioLabs
Description
The disclosed vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to insecure call of the unserialize() PHP function in untrusted user-input. A remote attacker can send specially crafted HTTP request to the affected system and delete arbitrary files on the system or display raw data output.