Impact
An authenticated Sulu administrator can generate or revoke preview links for resources without being required to have the VIEW permission for those resources. Because a preview link is a public URL that makes the target content reachable by an opaque token, the attacker or anyone who obtains the link can read content that should otherwise be restricted. The flaw is a classic authorization bypass that results in unintended information disclosure.
Affected Systems
The issue affects the Sulu content management system. Versions of Sulu before 2.6.25 (for the 2.x line) and before 3.0.8 (for the 3.x line) are vulnerable. This includes all deployments of Sulu where the preview-link endpoint and the PreviewLinkManager class are present.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score is not available, but the vulnerability requires that the attacker be a legitimate administrator who can identify target resource identifiers, a condition that is typically hard to satisfy without prior access to the system. Because the exploit produces a publicly accessible link that bypasses the view checks, the risk of accidental disclosure is significant even if the attacker cannot read the link directly. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment