CVE-2021-43836: PHP file inclusion in the Sulu admin panel
Sulu is an open-source PHP content management system based on the Symfony framework. In affected versions an attacker can read arbitrary local files via a PHP file include. In a default configuration this also leads to remote code execution. The problem is patched with the Versions 1.6.44, 2.2.18, 2.3.8, 2.4.0. For users unable to upgrade overwrite the service suluroute.generator.expressiontokenprovider and wrap the translator before passing it to the expression language.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-43836?
CVE-2021-43836 is a vulnerability in the Sulu content management system that allows an attacker to read arbitrary local files and potentially execute remote code.
What is the severity of CVE-2021-43836?
CVE-2021-43836 has a severity rating of 8.8, which is considered high.
How does CVE-2021-43836 affect Sulu?
CVE-2021-43836 affects Sulu versions up to and including 1.6.44, 2.0.0 to 2.2.18, and 2.3.0 to 2.3.8. It also affects Sulu 2.4.0-rc1.
How can an attacker exploit CVE-2021-43836?
An attacker can exploit CVE-2021-43836 by leveraging a PHP file inclusion vulnerability in Sulu, which allows them to read arbitrary local files and potentially execute remote code.
How can I patch CVE-2021-43836?
CVE-2021-43836 can be patched by updating to Sulu versions 1.6.44, 2.2.18, 2.3.8, or a later release.