Sulu is an open-source PHP content management system based on the Symfony framework. In versions before 1.6.43 are subject to stored cross site scripting attacks. HTML input into Tag names is not properly sanitized. Only admin users are allowed to create tags. Users are advised to upgrade.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-2208 Sulu is an open-source PHP content management system based on the Symfony framework. In versions before 1.6.43 are subject to stored cross site scripting attacks. HTML input into Tag names is not properly sanitized. Only admin users are allowed to create tags. Users are advised to upgrade.
Github GHSA Github GHSA GHSA-h58v-g3q6-q9fx Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in sulu/sulu
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-04T02:59:31.756Z

Reserved: 2021-09-15T00:00:00

Link: CVE-2021-41169

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-10-21T21:15:08.303

Modified: 2024-11-21T06:25:39.590

Link: CVE-2021-41169

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.