SB2021121549 - Multiple vulnerabilities in Sulu



SB2021121549 - Multiple vulnerabilities in Sulu

Published: December 15, 2021 Updated: May 12, 2026

Security Bulletin ID SB2021121549
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Incorrect User Management (CVE-ID: CVE-2021-43835)

The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to incorrect user management in the ProfileController putAction in the Sulu Admin panel when handling API requests. A remote user can modify their profile permissions to escalate privileges.

Only users who already have access to the admin UI are affected.


2) PHP file inclusion (CVE-ID: CVE-2021-43836)

The vulnerability allows a remote user to read arbitrary local files and execute arbitrary code.

The vulnerability exists due to improper control of file inclusion in the Sulu admin panel when processing crafted backend input. A remote user can trigger a PHP file include to read arbitrary local files and execute arbitrary code.

In a default configuration, the issue can lead to remote code execution.


Remediation

Install update from vendor's website.