AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-19790

MEDIUM · CVSS 6.1 EPSS 1.49%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-12-18 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2018-19790
Severity
MEDIUM
CVSS
6.1
EPSS
1.49%

Original NVD Description

An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9 and 4.2.x before 4.2.1. By using backslashes in the `_failure_path` input field of login forms, an attacker can work around the redirection target restrictions and effectively redirect the user to any domain after login.