CVE-2023-41336: symfony/ux-autocomplete Prevent injection of invalid entity ids for "autocomplete" fields

Affected Versions Versions < 2.11.1 are of the symfony/ux-autocomplete package are affected by this security issue. Description Under certain circumstances, an attacker could successfully submit an entity id for an EntityType that is not part of the… https://symfony.com/blog/cve-2023-41336-symfony-ux-autocomplete-prevent-injection-of-invalid-entity-ids-for-autocomplete-fields?utm_source=Symfony%20Blog%20Feed&utm_medium=feed

Erstellt 8mo | 11.09.2023, 14:20:23


Melden Sie sich an, um einen Kommentar hinzuzufügen

Andere Beiträge in dieser Gruppe

SymfonyCon Vienna 2024 - Submit your talk before July 8th

SymfonyCon Vienna 2024, our next annual International Symfony conference, will take place on December 5 & 6! Start preparing for your participation by submitting a paper for a talk or work

21.05.2024, 15:10:11 | Symfony
New in Symfony 7.1: Mapped Route Parameters

Contributed by Nicolas Grekas in #54720 and #54455.

Symfony maps route parameters to control

21.05.2024, 08:20:10 | Symfony
SymfonyLive Berlin 2024 postponed to 2025

We regret to inform you that for various reasons we've decided to postpone SymfonyLive Berlin 2024 to Spring 2025.

Exact dates, early bird registrations and Call for Papers will be announced s

20.05.2024, 14:10:12 | Symfony
New in Symfony 7.1: Commands Improvements

Symfony includes many commands to perform common operations in your applications. In Symfony 7.1, we are improving some commands with new options and features.

New Command to Reveal Secrets… https://

20.05.2024, 09:30:12 | Symfony
A Week of Symfony #907 (13-19 May 2024)

This week, the first release candidate version of Symfony 7.1 was published so you can test it in your own projects before the stable release in two weeks. Meanwhile, we continued publishing more talk

19.05.2024, 08:30:04 | Symfony
Symfony 7.1.0-RC1 released

Symfony 7.1.0-RC1 has just been released. Here is the list of the most important changes since 7.1.0-BETA1:

bug #54970 [DependencyInjection] Process PHP configs using the ContainerConfigurator (@
17.05.2024, 17:40:10 | Symfony
SymfonyOnline June 2024: Using Git magic for the Symfony mono-repo

SymfonyOnline June 2024 is just around the corner and will start on:

June 4-5: Workshop days. It is possible to attend 1 two-day training or 2 one-day trainings! June 6-7: Online conference

17.05.2024, 15:30:10 | Symfony