Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gfrh-gwqc-63cv

Опубликовано: 05 фев. 2024
Источник: github
Github: Прошло ревью

Описание

Sulu HTML Injection via Autocomplete Suggestion

Impact

It is an issue when input HTML into the Tag name. The HTML is execute when the tag name is listed in the auto complete form. Only admin users are affected and only admin users can create tags.

Patches

Has the problem been patched? What versions should users upgrade to?

The problem is patched with Version 2.4.16 and 2.5.12.

Workarounds

Is there a way for users to fix or remediate the vulnerability without upgrading?

Create a custom mutation observer

References

Are there any links users can visit to find out more?

Currently not.

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

sulu/sulu

composer
Затронутые версииВерсия исправления

>= 2.0.0, < 2.4.16

2.4.16

Наименование

sulu/sulu

composer
Затронутые версииВерсия исправления

>= 2.5.0, < 2.5.12

2.5.12

EPSS

Процентиль: 74%
0.00837
Низкий

Дефекты

CWE-79
CWE-80

Связанные уязвимости

CVSS3: 2.7
nvd
около 2 лет назад

Sulu is a highly extensible open-source PHP content management system based on the Symfony framework. There is an issue when inputting HTML into the Tag name. The HTML is executed when the tag name is listed in the auto complete form. Only admin users can create tags so they are the only ones affected. The problem is patched with version(s) 2.4.16 and 2.5.12.

EPSS

Процентиль: 74%
0.00837
Низкий

Дефекты

CWE-79
CWE-80