PT-2021-3511 · Sulu · Sulu

Alexander-Schranz

·

Published

2021-07-02

·

Updated

2021-07-09

·

CVE-2021-32737

CVSS v3.1

8.4

High

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sulu versions prior to 1.6.41
Description The issue is related to the lack of protection of the web page structure in the Sulu content management system, allowing a remote attacker to conduct cross-site scripting attacks. A logged-in admin user can add a script injection in the collection title, which can be executed. The problem is patched in version 1.6.41.
Recommendations For versions prior to 1.6.41, update to version 1.6.41 to resolve the issue. As a temporary workaround, manually patch the affected JavaScript files.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03560
CVE-2021-32737
GHSA-GM2X-6475-G9R8

Affected Products

Sulu