CVE-2018-13818: Code Injection
DISPUTED Twig before 2.4.4 allows Server-Side Template Injection (SSTI) via the search searchkey parameter. NOTE: the vendor points out that Twig itself is not a web application and states that it is the responsibility of web applications using Twig to properly wrap input to it.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this Twig vulnerability?
The vulnerability ID for this Twig vulnerability is CVE-2018-13818.
What is the severity of CVE-2018-13818?
The severity of CVE-2018-13818 is critical with a score of 9.8.
How does the vulnerability in Twig before 2.4.4 allow Server-Side Template Injection (SSTI)?
The vulnerability in Twig before 2.4.4 allows Server-Side Template Injection (SSTI) via the search search_key parameter.
What is the affected software for CVE-2018-13818?
The affected software for CVE-2018-13818 is Symfony Twig version up to exclusive version 2.4.4.
Is the Twig vendor responsible for properly securing input to Twig?
No, the vendor points out that Twig itself is not a web application and states that it is the responsibility of web applications using Twig to properly wrap input to it.