{"id":"CVE-2024-45592","summary":"auditor-bundle vulnerable to Cross-site Scripting because name of entity does not get escaped","details":"auditor-bundle, formerly known as DoctrineAuditBundle, integrates auditor library into any Symfony 3.4+ application. Prior to version 5.2.6, there is an unescaped entity property enabling Javascript injection. This is possible because `%source_label%` in twig macro is not escaped. Therefore script tags can be inserted and are executed. The vulnerability is fixed in versions 6.0.0 and 5.2.6.","aliases":["GHSA-78vg-7v27-hj67"],"modified":"2026-08-12T03:51:40.082169113Z","published":"2024-09-10T16:00:14.887Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/45xxx/CVE-2024-45592.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/45xxx/CVE-2024-45592.json"},{"type":"ADVISORY","url":"https://github.com/DamienHarper/auditor-bundle/security/advisories/GHSA-78vg-7v27-hj67"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-45592"},{"type":"FIX","url":"https://github.com/DamienHarper/auditor-bundle/commit/42ba2940d8b99467de0c806ea5655cc1c6882cd1"},{"type":"FIX","url":"https://github.com/DamienHarper/auditor-bundle/commit/e7deb377fa89677d44973b486d26d6a7374233ae"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/damienharper/auditor-bundle","events":[{"introduced":"9bd8d33dd1de2a10639284e5f2aa86794a1aabce"},{"fixed":"e7deb377fa89677d44973b486d26d6a7374233ae"},{"fixed":"42ba2940d8b99467de0c806ea5655cc1c6882cd1"}],"database_specific":{"extracted_events":[{"introduced":"5.0.0"},{"fixed":"5.2.6"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:damienharper:auditor-bundle:*:*:*:*:*:*:*:*"}}],"versions":["5.2.5","5.2.4","5.2.3","5.2.2","5.2.1","5.2.0","5.1.1","5.1.0","5.0.3","5.0.2","5.0.1","5.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-45592.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L"}]}