PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-5541 Getsymphony CVE debrief

CVE-2017-5541 is a directory traversal issue in Symphony CMS that affects versions up to 2.6.9. According to the NVD record, the flaw is in template/usererror.missing_extension.php and can let a remote attacker influence file rename behavior through crafted existing-folder and new-folder values containing dot-dot path segments. The issue was publicly published on 2017-01-20 and later had its NVD record modified on 2026-05-13. A fix is referenced in Symphony CMS 2.6.10.

Vendor
Getsymphony
Product
Symphony
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2017-01-20
Original CVE updated
2026-05-13
Advisory published
2017-01-20
Advisory updated
2026-05-13

Who should care

Administrators, maintainers, and hosting teams running Symphony CMS 2.6.9 or earlier should review this issue, especially where the affected template path and file-management workflows are reachable from untrusted users.

Technical summary

NVD classifies the weakness as CWE-22 (Path Traversal) with CVSS 3.0 vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N. The vulnerable component is template/usererror.missing_extension.php, and the reported attack condition is use of .. sequences in the existing-folder and new-folder parameters to manipulate filesystem path handling during rename operations. The documented impact is integrity-only at low severity, and the vulnerable version range ends at 2.6.9; 2.6.10 is the referenced fixed release.

Defensive priority

Medium. The issue is network-reachable and requires no privileges or user interaction, but the documented impact is limited to low integrity impact rather than full compromise.

Recommended defensive actions

  • Upgrade Symphony CMS to 2.6.10 or later as referenced by the vendor release notes.
  • Inventory deployments to confirm whether any instances are still on 2.6.9 or earlier.
  • Review file-rename and folder-handling code paths for path normalization and traversal checks.
  • Restrict access to administrative or file-management features to trusted users only.
  • Monitor application logs for unexpected rename activity or anomalous path inputs.
  • Validate backups and recovery procedures before applying the update.

Evidence notes

The supplied NVD metadata states the vulnerability is in Symphony CMS (cpe:2.3:a:getsymphony:symphony) through version 2.6.9, uses CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N, and maps to CWE-22. The referenced corpus includes a Symphony CMS issue record and the 2.6.10 release notes, which are consistent with remediation in that release. CVE publishedAt is 2017-01-20T08:59:00.470Z; modifiedAt is 2026-05-13T00:24:29.033Z.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-5541 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-5541

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-5541 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5541

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.