SB2024030446 - Improper access control in Sulu
Published: March 4, 2024 Updated: May 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper access control (CVE-ID: CVE-2024-27915)
The vulnerability allows a remote user to bypass page access restrictions.
The vulnerability exists due to improper access control in page access control for secured webspaces when handling page access requests. A remote user can access pages regardless of configured role permissions to bypass page access restrictions.
Only webspaces with a security system configured and permission checks enabled are affected.
Remediation
Install update from vendor's website.