Impact
The vulnerability allows an authenticated backend user with edit rights on one collection to move media from a restricted collection by specifying a client‑supplied collection value, bypassing permission checks. The effect is that the attacker can retrieve media they are not authorized to view or download, exposing confidential content. This is a classic Insecure Direct Object Reference flaw documented as CWE‑639 and CWE‑863.
Affected Systems
All instances of the Sulu content management system running a version older than 2.6.25 or 3.0.8 are affected. The issue resides in the MediaManager component of the media bundle.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower probability of widespread exploitation. However, the attack requires only an authenticated backend user with edit permission on a collection, a role that exists in many installations. An attacker can directly move the media item and then access the content, so the risk to confidentiality is significant for affected sites.
OpenCVE Enrichment