PT-2024-32676 · Unknown+2 · Sulumediabundle+2

Wachterjohannes

·

Published

2024-10-03

·

Updated

2024-10-08

·

CVE-2024-47617

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Sulu versions prior to 2.6.5 Sulu versions prior to 2.5.21
Description This issue allows an attacker to inject arbitrary HTML/JavaScript code through the media download URL in Sulu CMS, affecting the SuluMediaBundle component. It is a Reflected Cross-Site Scripting (XSS) issue, which could potentially allow attackers to steal sensitive information, manipulate the website's content, or perform actions on behalf of the victim.
Recommendations For versions prior to 2.6.5, update to version 2.6.5 or later. For versions prior to 2.5.21, update to version 2.5.21 or later. As a temporary workaround, consider implementing additional input validation and output encoding for the slug parameter in the MediaStreamController's downloadAction method. Alternatively, configuring a Web Application Firewall (WAF) to filter potentially malicious input could serve as a temporary mitigation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-47617
GHSA-6784-9C82-VR85

Affected Products

Sulu
Sulu Cms
Sulumediabundle