CVE-2019-10910 is a critical vulnerability affecting multiple versions of Symfony (before 2.7.51, 2.8.50, 3.4.26, 4.1.12, and 4.2.7) and related products like Drupal. It stems from improper handling of user input in service IDs within the symfony/dependency-injection component, potentially leading to SQL Injection and remote code execution. With a CVSS score of 9.8 (CRITICAL) and an EPSS percentile of 93.7%, this vulnerability is easily exploitable over the network with low attack complexity, allowing for complete compromise of confidentiality, integrity, and availability. While not currently on CISA's KEV catalog or having public exploit code like Metasploit, its high FAUCET Risk Score of 90/100, community discussion, and media coverage indicate significant attention and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.7.0, < 2.7.51CPE matchmatch criteria | cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:* | ||
>= 2.8.0, < 2.8.50CPE matchmatch criteria | cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:* | ||
>= 3.4.0, < 3.4.26CPE matchmatch criteria | cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:* | ||
>= 4.1.0, < 4.1.12CPE matchmatch criteria | cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:* | ||
>= 4.2.0, < 4.2.7CPE matchmatch criteria | cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.