Sulu is a PHP content management system. This vulnerability allows an attacker to inject arbitrary HTML/JavaScript code through the media download URL in Sulu CMS. It affects the SuluMediaBundle component. The vulnerability is a Reflected Cross-Site Scripting (XSS) issue, which could potentially allow attackers to steal sensitive information, manipulate the website's content, or perform actions on behalf of the victim. This vulnerability is fixed in 2.6.5 and 2.5.21.
History

Tue, 08 Oct 2024 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Sulu
Sulu sulu
CPEs cpe:2.3:a:sulu:sulu:2.5.20:*:*:*:*:*:*:*
cpe:2.3:a:sulu:sulu:2.6.4:*:*:*:*:*:*:*
Vendors & Products Sulu
Sulu sulu

Tue, 08 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 03 Oct 2024 14:30:00 +0000

Type Values Removed Values Added
Description Sulu is a PHP content management system. This vulnerability allows an attacker to inject arbitrary HTML/JavaScript code through the media download URL in Sulu CMS. It affects the SuluMediaBundle component. The vulnerability is a Reflected Cross-Site Scripting (XSS) issue, which could potentially allow attackers to steal sensitive information, manipulate the website's content, or perform actions on behalf of the victim. This vulnerability is fixed in 2.6.5 and 2.5.21.
Title Reflected XSS Vulnerability in Sulu Media Bundle
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-10-03T14:24:44.300Z

Updated: 2024-10-08T13:33:43.219Z

Reserved: 2024-09-27T20:37:22.121Z

Link: CVE-2024-47617

cve-icon Vulnrichment

Updated: 2024-10-08T13:33:35.962Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-03T15:15:14.937

Modified: 2024-10-08T14:23:38.597

Link: CVE-2024-47617

cve-icon Redhat

No data.