CVE-2021-32737: XSS Injection in Media Collection Title was possible
Sulu is an open-source PHP content management system based on the Symfony framework. In versions of Sulu prior to 1.6.41, it is possible for a logged in admin user to add a script injection (cross-site-scripting) in the collection title. The problem is patched in version 1.6.41. As a workaround, one may manually patch the affected JavaScript files in lieu of updating.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-32737?
CVE-2021-32737 is a vulnerability in Sulu, an open-source PHP content management system, that allows a logged-in admin user to add a script injection (cross-site scripting) in the collection title.
What is the severity of CVE-2021-32737?
The severity of CVE-2021-32737 is high, with a severity value of 4.8.
How can I fix CVE-2021-32737?
To fix CVE-2021-32737, you should update Sulu to version 1.6.41 or newer, as the problem is patched in this version.
Is there a workaround for CVE-2021-32737?
As a workaround, you can ensure that only trusted admin users have access to the collection title input field.
Where can I find more information about CVE-2021-32737?
You can find more information about CVE-2021-32737 on the Sulu GitHub page, specifically the release notes for version 1.6.41, and the security advisories section.