The displayBlock function Template.php in Sensio Labs Twig before 1.20.0, when Sandbox mode is enabled, allows remote attackers to execute arbitrary code via the _self variable in a template.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| twig/twig(Packagist) | 0 | 1.20.0 | N/A |
CVSS Metrics