- Notifications
You must be signed in to change notification settings - Fork342
Security: sulu/sulu
Security
- Inject arbitrary HTML/JavaScript code through the media download URLGHSA-6784-9c82-vr85 published
Oct 3, 2024 bywachterjohannesModerate - Access to pages is granted regardless of role permissionsGHSA-jr83-m233-gg6p published
Mar 4, 2024 byalexander-schranzModerate - HTML Injection via Autocomplete SuggestionGHSA-gfrh-gwqc-63cv published
Feb 5, 2024 byalexander-schranzLow - Observable Response Discrepancy on Admin LoginGHSA-wmwf-49vv-p3mr published
Aug 3, 2023 byalexander-schranzModerate - XSS via uploaded SVGGHSA-255w-87rh-rg44 published
Oct 3, 2024 bywachterjohannesModerate - Privilege escalation in the Sulu Admin panelGHSA-84px-q68r-2fc9 published
Dec 15, 2021 byalexander-schranzModerate - PHP file inclusion in the Sulu admin panelGHSA-vx6j-pjrh-vgjh published
Dec 15, 2021 byalexander-schranzModerate - XSS injection in Tag autocomplete was possibleGHSA-h58v-g3q6-q9fx published
Oct 21, 2021 byalexander-schranzLow - XSS Injection in Media Collection Title was possibleGHSA-gm2x-6475-g9r8 published
Jul 2, 2021 byalexander-schranzLow - Reset Password / Login vulnerabilityGHSA-wfm4-pq59-wg6r published
Aug 3, 2020 bydanrotModerate
Learn more about advisories related tosulu/sulu in theGitHub Advisory Database