Medium
CVSS 6.8
Overview
The displayBlock function Template.php in Sensio Labs Twig before 1.20.0, when Sandbox mode is enabled, allows remote attackers to execute arbitrary code via the _self variable in a template.
The displayBlock function Template.php in Sensio Labs Twig before 1.20.0, when S...
The displayBlock function Template.php in Sensio Labs Twig before 1.20.0, when Sandbox mode is enabled, allows remote attackers to execute arbitrary code via the _self variable in a template.
This vulnerability is rated 🟡 MEDIUM.
Recommended actions: