CVE-2024-47617

Sulu is a PHP content management system. This vulnerability allows an attacker to inject arbitrary HTML/JavaScript code through the media download URL in Sulu CMS. It affects the SuluMediaBundle component. The vulnerability is a Reflected Cross-Site Scripting (XSS) issue, which could potentially allow attackers to steal sensitive information, manipulate the website's content, or perform actions on behalf of the victim. This vulnerability is fixed in 2.6.5 and 2.5.21.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sulu:sulu:2.5.20:*:*:*:*:*:*:*
cpe:2.3:a:sulu:sulu:2.6.4:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-10-03 15:15

Updated : 2024-10-08 14:23


NVD link : CVE-2024-47617

Mitre link : CVE-2024-47617

CVE.ORG link : CVE-2024-47617


JSON object : View

Products Affected

sulu

  • sulu
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')