Filtered by vendor 21degrees Subscriptions
Total 3 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-36610 1 21degrees 1 Symphony 2024-12-04 9.8 Critical
A deserialization vulnerability exists in the Stub class of the VarDumper module in Symfony v7.0.3. The vulnerability stems from deficiencies in the original implementation when handling properties with null or uninitialized values. An attacker could construct specific serialized data and use this vulnerability to execute unauthorized code. NOTE: the Supplier has concluded that this is a false report.
CVE-2008-3592 1 21degrees 1 Symphony 2024-11-21 N/A
Unrestricted file upload vulnerability in the File Manager in the admin panel in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension to a directory specified in the destination parameter, then accessing the uploaded file via a direct request, as demonstrated using workspace/masters/.
CVE-2008-3591 1 21degrees 1 Symphony 2024-11-21 N/A
SQL injection vulnerability in lib/class.admin.php in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers to execute arbitrary SQL commands via the sym_auth cookie in a /publish/filemanager/ request to index.php.