CVE-2025-24374

Twig is a template language for PHP. When using the ?? operator, output escaping was missing for the expression on the left side of the operator. This vulnerability is fixed in 3.19.0.
Configurations

No configuration.

History

29 Jan 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-29 16:15

Updated : 2025-01-29 16:15


NVD link : CVE-2025-24374

Mitre link : CVE-2025-24374

CVE.ORG link : CVE-2025-24374


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')