#VU18300 Improper input validation in Symfony - CVE-2019-10913
Published: April 18, 2019
Symfony
SensioLabs
Description
The disclosed vulnerability allows a remote attacker to bypass certain security restrictions.
The vulnerability exists due to absent validation of HTTP methods when processing methods directly or via X-Http-Method-Override header. A remote attacker can pass specially crafted string as HTTP method and bypass certain security restrictions.