PT-2024-32676 · Unknown+2 · Sulumediabundle+2
Wachterjohannes
·
Published
2024-10-03
·
Updated
2024-10-08
·
CVE-2024-47617
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Sulu versions prior to 2.6.5
Sulu versions prior to 2.5.21
Description
This issue allows an attacker to inject arbitrary HTML/JavaScript code through the media download URL in Sulu CMS, affecting the SuluMediaBundle component. It is a Reflected Cross-Site Scripting (XSS) issue, which could potentially allow attackers to steal sensitive information, manipulate the website's content, or perform actions on behalf of the victim.
Recommendations
For versions prior to 2.6.5, update to version 2.6.5 or later.
For versions prior to 2.5.21, update to version 2.5.21 or later.
As a temporary workaround, consider implementing additional input validation and output encoding for the
slug parameter in the MediaStreamController's downloadAction method.
Alternatively, configuring a Web Application Firewall (WAF) to filter potentially malicious input could serve as a temporary mitigation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sulu
Sulu Cms
Sulumediabundle