Project: 
Project machine name: 
webprofiler
Date: 
2023-September-06
Vulnerability: 
Cross Site Scripting
Affected versions: 
>=10.1.0 <10.1.1
Description: 

The Webprofiler module provides a way of displaying the Symfony profile debugging tool at the bottom of each page.

The abbr_class Twig filter can be used to bypass the Twig auto-escape feature.

This vulnerability is mitigated by the fact that it is only exposed when the filter is specifically used in a theme to render content that contains an attack vector.

Solution: 

Install the latest version:

Reported By: 
Coordinated By: