PHP file inclusion in Sulu - CVE-2021-43836

 

PHP file inclusion in Sulu - CVE-2021-43836

Published: December 15, 2021 / Updated: May 12, 2026


Vulnerability identifier: #VU131111
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-43836
CWE-ID: CWE-98
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to read arbitrary local files and execute arbitrary code.

The vulnerability exists due to improper control of file inclusion in the Sulu admin panel when processing crafted backend input. A remote user can trigger a PHP file include to read arbitrary local files and execute arbitrary code.

In a default configuration, the issue can lead to remote code execution.


Affected software

Sulu

How to mitigate CVE-2021-43836

Install security update from vendor's website.

Sulu - addressed in versions 1.6.44, 2.2.18, 2.3.8, 2.4.0

External References

Related Security Bulletins