CVE-2016-2403
Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty p
Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.
CRITICAL · CVSS 9.8
EPSS 0.00154
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0