Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f6rx-hf55-4255

Опубликовано: 15 мая 2025
Источник: github
Github: Прошло ревью
CVSS4: 6.1

Описание

Sulu vulnerable to XXE in SVG File upload Inspector

Impact

A admin user can upload SVG which may load external data via XML DOM library, specially this can be used for eventually reference none secure XML External Entity References.

Patches

The problem has not been patched yet. Users should upgrade to patched versions once they become available. Currently affected versions are:

  • 2.6.9
  • 2.5.25
  • 3.0.0-alpha3

Workarounds

Patch the effect file src/Sulu/Bundle/MediaBundle/FileInspector/SvgFileInspector.php in sulu with:

-$dom->loadXML($svg, \LIBXML_NOENT | \LIBXML_DTDLOAD); +$dom->loadXML($data, LIBXML_NONET);

References

Пакеты

Наименование

sulu/sulu

composer
Затронутые версииВерсия исправления

>= 2.5.21, < 2.5.25

2.5.25

Наименование

sulu/sulu

composer
Затронутые версииВерсия исправления

>= 2.6.5, < 2.6.9

2.6.9

Наименование

sulu/sulu

composer
Затронутые версииВерсия исправления

>= 3.0.0-alpha1, < 3.0.0-alpha3

3.0.0-alpha3

EPSS

Процентиль: 19%
0.0006
Низкий

6.1 Medium

CVSS4

Дефекты

CWE-611

Связанные уязвимости

nvd
9 месяцев назад

Sulu is an open-source PHP content management system based on the Symfony framework. Starting in versions 2.5.21, 2.6.5, and 3.0.0-alpha1, an admin user can upload SVG which may load external data via XML DOM library. This can be used for insecure XML External Entity References. The problem has been patched in versions 2.6.9, 2.5.25, and 3.0.0-alpha3. As a workaround, one may patch the effect file `src/Sulu/Bundle/MediaBundle/FileInspector/SvgFileInspector.php` manually.

EPSS

Процентиль: 19%
0.0006
Низкий

6.1 Medium

CVSS4

Дефекты

CWE-611