{"id":"CVE-2015-7809","aliases":[],"url":"https://o3.security/vulnerability/CVE-2015-7809","summary":"Twig remote code execution in templates","details":"The `displayBlock` function `Template.php` in Sensio Labs Twig before 1.20.0, when Sandbox mode is enabled, allows remote attackers to execute arbitrary code via the `_self` variable in a template.","published":"2022-05-14T02:03:50Z","modified":"2024-05-30T13:26:54.932820Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"twig/twig","fixedVersion":"1.20.0"}],"fix":{"url":"https://github.com/twigphp/Twig/pull/1759","label":"twigphp/Twig#1759"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-7809"},{"type":"WEB","url":"https://github.com/twigphp/Twig/pull/1759"},{"type":"WEB","url":"https://github.com/twigphp/Twig/commit/30be07759a3de2558da5224f127d052ecf492e8f"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/twig/twig/CVE-2015-7809.yaml"},{"type":"PACKAGE","url":"https://github.com/twigphp/Twig"},{"type":"WEB","url":"https://symfony.com/blog/security-release-twig-1-20-0"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2015/08/21/3"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2015/10/11/2"},{"type":"WEB","url":"http://symfony.com/blog/security-release-twig-1-20-0"},{"type":"WEB","url":"http://www.debian.org/security/2015/dsa-3343"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-05-30T13:26:54.932820Z"}}