Vulnerability Details CVE-2016-2403
Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 36.9%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2016-2403
-
cpe:2.3:a:sensiolabs:symfony:2.8.0
-
cpe:2.3:a:sensiolabs:symfony:2.8.1
-
cpe:2.3:a:sensiolabs:symfony:2.8.2
-
cpe:2.3:a:sensiolabs:symfony:2.8.3
-
cpe:2.3:a:sensiolabs:symfony:2.8.4
-
cpe:2.3:a:sensiolabs:symfony:2.8.5
-
cpe:2.3:a:sensiolabs:symfony:3.0.0
-
cpe:2.3:a:sensiolabs:symfony:3.0.1
-
cpe:2.3:a:sensiolabs:symfony:3.0.2
-
cpe:2.3:a:sensiolabs:symfony:3.0.3
-
cpe:2.3:a:sensiolabs:symfony:3.0.4
-
cpe:2.3:a:sensiolabs:symfony:3.0.5