Sulu

Sulu

11 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.07%
  • Veröffentlicht 14.05.2025 15:29:08
  • Zuletzt bearbeitet 16.05.2025 14:43:56

Sulu is an open-source PHP content management system based on the Symfony framework. Starting in versions 2.5.21, 2.6.5, and 3.0.0-alpha1, an admin user can upload SVG which may load external data via XML DOM library. This can be used for insecure XM...

  • EPSS 1.61%
  • Veröffentlicht 03.10.2024 15:15:15
  • Zuletzt bearbeitet 08.10.2024 14:31:08

Sulu is a PHP content management system. Sulu is vulnerable against XSS whereas a low privileged user with access to the “Media” section can upload an SVG file with a malicious payload. Once uploaded and accessed, the malicious javascript will be exe...

  • EPSS 0.75%
  • Veröffentlicht 03.10.2024 15:15:14
  • Zuletzt bearbeitet 08.10.2024 14:23:38

Sulu is a PHP content management system. This vulnerability allows an attacker to inject arbitrary HTML/JavaScript code through the media download URL in Sulu CMS. It affects the SuluMediaBundle component. The vulnerability is a Reflected Cross-Site ...

  • EPSS 0.16%
  • Veröffentlicht 06.03.2024 20:15:47
  • Zuletzt bearbeitet 08.01.2025 18:37:37

Sulu is a PHP content management system. Starting in verson 2.2.0 and prior to version 2.4.17 and 2.5.13, access to pages is granted regardless of role permissions for webspaces which have a security system configured and permission check enabled. We...

  • EPSS 0.84%
  • Veröffentlicht 05.02.2024 21:15:12
  • Zuletzt bearbeitet 21.11.2024 08:59:45

Sulu is a highly extensible open-source PHP content management system based on the Symfony framework. There is an issue when inputting HTML into the Tag name. The HTML is executed when the tag name is listed in the auto complete form. Only admin user...

  • EPSS 0.36%
  • Veröffentlicht 04.08.2023 01:15:10
  • Zuletzt bearbeitet 21.11.2024 08:15:11

Sulu is an open-source PHP content management system based on the Symfony framework. It allows over the Admin Login form to detect which user (username, email) exists and which one do not exist. Sulu Installation not using the old Symfony 5.4 securit...

  • EPSS 0.32%
  • Veröffentlicht 15.12.2021 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:29:53

Sulu is an open-source PHP content management system based on the Symfony framework. In affected versions Sulu users who have access to any subset of the admin UI are able to elevate their privilege. Over the API it was possible for them to give them...

  • EPSS 4.29%
  • Veröffentlicht 15.12.2021 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:29:53

Sulu is an open-source PHP content management system based on the Symfony framework. In affected versions an attacker can read arbitrary local files via a PHP file include. In a default configuration this also leads to remote code execution. The prob...

  • EPSS 0.29%
  • Veröffentlicht 21.10.2021 21:15:08
  • Zuletzt bearbeitet 21.11.2024 06:25:39

Sulu is an open-source PHP content management system based on the Symfony framework. In versions before 1.6.43 are subject to stored cross site scripting attacks. HTML input into Tag names is not properly sanitized. Only admin users are allowed to cr...

  • EPSS 0.36%
  • Veröffentlicht 02.07.2021 18:15:09
  • Zuletzt bearbeitet 21.11.2024 06:07:38

Sulu is an open-source PHP content management system based on the Symfony framework. In versions of Sulu prior to 1.6.41, it is possible for a logged in admin user to add a script injection (cross-site-scripting) in the collection title. The problem ...