Security Advisory

CVE-2015-7809

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2015-11-06 21:00:00
Last updated 2024-08-06 07:58:59
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The displayBlock function Template.php in Sensio Labs Twig before 1.20.0, when Sandbox mode is enabled, allows remote attackers to execute arbitrary code via the _self variable in a template.