{"id":"UBUNTU-CVE-2018-12040","details":"** DISPUTED ** Reflected Cross-site scripting (XSS) vulnerability in the web profiler in SensioLabs Symfony 3.3.6 allows remote attackers to inject arbitrary web script or HTML via the \"file\" parameter, aka an _profiler/open?file= URI.  NOTE: The vendor states \"The XSS ... is in the web profiler, a tool that should never be deployed in production (so, we don't handle those issues as security issues).\"","modified":"2018-06-13T22:29:00Z","published":"2018-06-13T22:29:00Z","withdrawn":"2025-06-23T15:53:11Z","references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2018-12040"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1590702"},{"type":"REPORT","url":"http://packetstormsecurity.com/files/148125/SensioLabs-Symfony-3.3.6-Cross-Site-Scripting.html"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2018-12040"}],"affected":[{"package":{"name":"symfony","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/symfony"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.7.1+dfsg-1","2.7.5+dfsg-1","2.7.9+dfsg-1","2.7.9+dfsg-1ubuntu2","2.7.10-0ubuntu2"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-12040.json"}},{"package":{"name":"symfony","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/symfony"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.8.7+dfsg-1.3ubuntu1","3.4.3+dfsg-1ubuntu4","3.4.6+dfsg-1","3.4.6+dfsg-1ubuntu0.1","3.4.6+dfsg-1ubuntu0.1+esm1","3.4.6+dfsg-1ubuntu0.1+esm2"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-12040.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}