#VU26531 Information Exposure Through an Error Message in Symfony - CVE-2020-5274
Published: April 2, 2020 / Updated: April 3, 2020
Symfony
SensioLabs
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to some properties of the Exception are not properly escaped when the "ErrorHandler" renderes it stacktrace. A remote authenticated attacker can gain unauthorized access to sensitive information on the system.