Symphony is prone to following multiple remote security vulnerabilities:
1. An authentication-bypass vulnerability
2. Multiple cross-site-scripting vulnerabilities
3. An HTML-injection vulnerability
4. Multiple SQL-injection vulnerabilities
An attacker may leverage these issues to run malicious HTML and script codes in the context of the affected browser, steal cookie-based authentication credentials, to gain unauthorized access to the affected application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Proof of Concept:
An attacker can exploit these issues through a browser. An attacker must trick an unsuspecting victim into following a malicious URI to exploit the cross-site scripting issues.
The following example URI is available: