CVE-2021-32737

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
02/07/2021
Last modified:
09/07/2021

Description

Sulu is an open-source PHP content management system based on the Symfony framework. In versions of Sulu prior to 1.6.41, it is possible for a logged in admin user to add a script injection (cross-site-scripting) in the collection title. The problem is patched in version 1.6.41. As a workaround, one may manually patch the affected JavaScript files in lieu of updating.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sulu:sulu:*:*:*:*:*:*:*:* 1.6.41 (excluding)