Incorrect User Management in Sulu - CVE-2021-43835
Published: December 15, 2021 / Updated: May 12, 2026
Sulu
Detailed vulnerability description
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to incorrect user management in the ProfileController putAction in the Sulu Admin panel when handling API requests. A remote user can modify their profile permissions to escalate privileges.
Only users who already have access to the admin UI are affected.