Sulu

Sulu

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.52%
  • Veröffentlicht 05.02.2024 21:15:12
  • Zuletzt bearbeitet 21.11.2024 08:59:45

Sulu is a highly extensible open-source PHP content management system based on the Symfony framework. There is an issue when inputting HTML into the Tag name. The HTML is executed when the tag name is listed in the auto complete form. Only admin user...

  • EPSS 0.62%
  • Veröffentlicht 04.08.2023 01:15:10
  • Zuletzt bearbeitet 21.11.2024 08:15:11

Sulu is an open-source PHP content management system based on the Symfony framework. It allows over the Admin Login form to detect which user (username, email) exists and which one do not exist. Sulu Installation not using the old Symfony 5.4 securit...

  • EPSS 1.98%
  • Veröffentlicht 15.12.2021 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:29:53

Sulu is an open-source PHP content management system based on the Symfony framework. In affected versions an attacker can read arbitrary local files via a PHP file include. In a default configuration this also leads to remote code execution. The prob...

  • EPSS 1.13%
  • Veröffentlicht 15.12.2021 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:29:53

Sulu is an open-source PHP content management system based on the Symfony framework. In affected versions Sulu users who have access to any subset of the admin UI are able to elevate their privilege. Over the API it was possible for them to give them...

  • EPSS 0.59%
  • Veröffentlicht 21.10.2021 21:15:08
  • Zuletzt bearbeitet 21.11.2024 06:25:39

Sulu is an open-source PHP content management system based on the Symfony framework. In versions before 1.6.43 are subject to stored cross site scripting attacks. HTML input into Tag names is not properly sanitized. Only admin users are allowed to cr...

  • EPSS 0.67%
  • Veröffentlicht 02.07.2021 18:15:09
  • Zuletzt bearbeitet 21.11.2024 06:07:38

Sulu is an open-source PHP content management system based on the Symfony framework. In versions of Sulu prior to 1.6.41, it is possible for a logged in admin user to add a script injection (cross-site-scripting) in the collection title. The problem ...

Exploit
  • EPSS 1.11%
  • Veröffentlicht 05.08.2020 21:15:12
  • Zuletzt bearbeitet 21.11.2024 05:04:54

In Sulu before versions 1.6.35, 2.0.10, and 2.1.1, when the "Forget password" feature on the login screen is used, Sulu asks the user for a username or email address. If the given string is not found, a response with a `400` error code is returned, a...