Описание
Sulu is an open-source PHP content management system based on the Symfony framework. It allows over the Admin Login form to detect which user (username, email) exists and which one do not exist. Sulu Installation not using the old Symfony 5.4 security System and previous version are not impacted by this Security issue. The vulnerability has been patched in version 2.5.10.
Ссылки
- Patch
- Release Notes
- MitigationVendor Advisory
- Patch
- Release Notes
- MitigationVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 2.5.0 (включая) до 2.5.10 (исключая)
cpe:2.3:a:sulu:sulu:*:*:*:*:*:*:*:*
EPSS
Процентиль: 58%
0.00362
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-204
Связанные уязвимости
CVSS3: 4.3
github
больше 2 лет назад
Sulu Observable Response Discrepancy on Admin Login
EPSS
Процентиль: 58%
0.00362
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-204