Skip to content
COOEY

EXPOSURES › CVE-2020-25912

CVE-2020-25912

CRITICAL
DETAIL
SourceNVD · cve Published2021-10-31 CVSS9.1 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-25912 ↗
SHAME 35/100

A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS).

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS).

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.80
CVE-2020-25912 (Symphony) is a critical XXE vulnerability in a widely used CMS, leading to information disclosure and DoS risks, with no evidence of vendor remediation or praise in provided sources.
www.hipaajournal.com ↗ severe-fallout -0.90
Negative - unrelated breach
"Accenture Confirms Intrusion After Hacker Claims 35GB Data Breach"
x.com ↗ severe-fallout -0.90
Negative - unrelated breach
"BREAKING: Apple accuses an OpenAI employee of hacking its systems"
dailysecurityreview.com ↗ severe-fallout -0.90
Negative - unrelated breach
"Broadcom Employee Data Leaked After Supply Chain Breach at ADP Partner"
www.nextgov.com ↗ severe-fallout -0.90
Negative - unrelated breach
"Hackers breached DHS information-sharing network, people familiar say"
cooey ↗ severe-fallout -0.50
Neutral reporting of vulnerability
"A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS)."
www.cvefind.com ↗ severe-fallout +0.00
Neutral database listing
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.