Medium severity6.1NVD Advisory· Published Aug 11, 2020· Updated Jun 17, 2026
CVE-2020-15071
CVE-2020-15071
Description
content/content.blueprintsevents.php in Symphony CMS 3.0.0 allows XSS via fields['name'] to appendSubheading.
Affected products
3- Symphony/CMSdescription
- cpe:2.3:a:getsymphony:symphony:3.0.0:*:*:*:*:*:*:*
- Range: =3.0.0
Patches
Vulnerability mechanics
References
1- github.com/symphonycms/symphonycms/issues/2917nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.