Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-14948 | Sulu vulnerable to XXE in SVG File upload Inspector |
Github GHSA |
GHSA-f6rx-hf55-4255 | Sulu vulnerable to XXE in SVG File upload Inspector |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 14 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 14 May 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Sulu is an open-source PHP content management system based on the Symfony framework. Starting in versions 2.5.21, 2.6.5, and 3.0.0-alpha1, an admin user can upload SVG which may load external data via XML DOM library. This can be used for insecure XML External Entity References. The problem has been patched in versions 2.6.9, 2.5.25, and 3.0.0-alpha3. As a workaround, one may patch the effect file `src/Sulu/Bundle/MediaBundle/FileInspector/SvgFileInspector.php` manually. | |
| Title | Sulu vulnerable to XXE in SVG File upload Inspector | |
| Weaknesses | CWE-611 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-05-14T18:13:14.564Z
Reserved: 2025-05-09T19:49:35.620Z
Link: CVE-2025-47778
Updated: 2025-05-14T18:13:11.667Z
Status : Awaiting Analysis
Published: 2025-05-14T16:15:29.110
Modified: 2025-05-16T14:43:56.797
Link: CVE-2025-47778
No data.
OpenCVE Enrichment
Updated: 2025-06-23T19:31:58Z
EUVD
Github GHSA