Sulu is a highly extensible open-source PHP content management system based on the Symfony framework. There is an issue when inputting HTML into the Tag name. The HTML is executed when the tag name is listed in the auto complete form. Only admin users can create tags so they are the only ones affected. The problem is patched with version(s) 2.4.16 and 2.5.12.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-0641 Sulu is a highly extensible open-source PHP content management system based on the Symfony framework. There is an issue when inputting HTML into the Tag name. The HTML is executed when the tag name is listed in the auto complete form. Only admin users can create tags so they are the only ones affected. The problem is patched with version(s) 2.4.16 and 2.5.12.
Github GHSA Github GHSA GHSA-gfrh-gwqc-63cv Sulu HTML Injection via Autocomplete Suggestion
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-01T23:28:12.885Z

Reserved: 2024-01-31T16:28:17.941Z

Link: CVE-2024-24807

cve-icon Vulnrichment

Updated: 2024-08-01T23:28:12.885Z

cve-icon NVD

Status : Modified

Published: 2024-02-05T21:15:12.557

Modified: 2024-11-21T08:59:45.297

Link: CVE-2024-24807

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses