MValle21 / snipe-it

A free open source IT asset/license management system
https://snipeitapp.com
GNU Affero General Public License v3.0
0 stars 0 forks source link

CVE-2016-10991 (High) detected in symfony/dom-crawler-v3.1.10 - autoclosed #10

Closed mend-for-github-com[bot] closed 1 year ago

mend-for-github-com[bot] commented 3 years ago

CVE-2016-10991 - High Severity Vulnerability

Vulnerable Library - symfony/dom-crawler-v3.1.10

Symfony DomCrawler Component

Library home page: https://api.github.com/repos/symfony/dom-crawler/zipball/7eede2a901a19928494194f7d1815a77b9a473a0

Dependency Hierarchy: - :x: **symfony/dom-crawler-v3.1.10** (Vulnerable Library)

Found in HEAD commit: 6937a6413a72bc7060c19b8195035c2b9504cbd2

Found in base branch: master

Vulnerability Details

The imdb-widget plugin before 1.0.9 for WordPress has Local File Inclusion.

Publish Date: 2019-09-17

URL: CVE-2016-10991

CVSS 3 Score Details (7.5)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: High - Integrity Impact: None - Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10991

Release Date: 2019-09-17

Fix Resolution: 1.0.9

mend-for-github-com[bot] commented 1 year ago

:heavy_check_mark: This issue was automatically closed by Mend because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the Mend inventory.