EXPOSURES › CVE-2020-25912
CVE-2020-25912
CRITICAL
DETAIL
SourceNVD · cve
Published2021-10-31
CVSS9.1
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-25912 ↗
SHAME 35/100
A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS).
▸ RECOMMENDED ACTION Critical severity — schedule patching of the affected products.
PLAYERS IMPLICATED
DESCRIPTION
A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS).
SENTIMENT · TRUSTED SOURCES
synthesis
severe-fallout
-0.80
CVE-2020-25912 (Symphony) is a critical XXE vulnerability in a widely used CMS, leading to information disclosure and DoS risks, with no evidence of vendor remediation or praise in provided sources.
Negative - unrelated breach
"Accenture Confirms Intrusion After Hacker Claims 35GB Data Breach"
Negative - unrelated breach
"BREAKING: Apple accuses an OpenAI employee of hacking its systems"
Negative - unrelated breach
"Broadcom Employee Data Leaked After Supply Chain Breach at ADP Partner"
Negative - unrelated breach
"Hackers breached DHS information-sharing network, people familiar say"
Neutral reporting of vulnerability
"A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS)."
Neutral database listing
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.