Twig is a template language for PHP. When using the ?? operator, output escaping was missing for the expression on the left side of the operator. This vulnerability is fixed in 3.19.0.
References
Configurations
No configuration.
History
29 Jan 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-29 16:15
Updated : 2025-01-29 16:15
NVD link : CVE-2025-24374
Mitre link : CVE-2025-24374
CVE.ORG link : CVE-2025-24374
JSON object : View
Products Affected
No product.
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')