The SuluFormBundle adds support for creating dynamic forms in Sulu Admin. The TokenController get parameter formName is not sanitized in the returned input field which leads to XSS. This vulnerability is fixed in 2.5.3.
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-06-06 16:15
Updated : 2024-06-07 14:56
NVD link : CVE-2024-37156
Mitre link : CVE-2024-37156
CVE.ORG link : CVE-2024-37156
JSON object : View
Products Affected
No product.