Sulu is an open-source PHP content management system based on the Symfony framework. It allows over the Admin Login form to detect which user (username, email) exists and which one do not exist. Sulu Installation not using the old Symfony 5.4 security System and previous version are not impacted by this Security issue. The vulnerability has been patched in version 2.5.10.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-2374 Sulu is an open-source PHP content management system based on the Symfony framework. It allows over the Admin Login form to detect which user (username, email) exists and which one do not exist. Sulu Installation not using the old Symfony 5.4 security System and previous version are not impacted by this Security issue. The vulnerability has been patched in version 2.5.10.
Github GHSA Github GHSA GHSA-wmwf-49vv-p3mr Sulu Observable Response Discrepancy on Admin Login
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 03 Oct 2024 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-10-03T18:21:46.144Z

Reserved: 2023-07-28T13:26:46.476Z

Link: CVE-2023-39343

cve-icon Vulnrichment

Updated: 2024-08-02T18:02:06.889Z

cve-icon NVD

Status : Modified

Published: 2023-08-04T01:15:10.250

Modified: 2024-11-21T08:15:11.757

Link: CVE-2023-39343

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.