Cross-site scripting in Sulu - CVE-2024-47617
Published: October 3, 2024 / Updated: May 12, 2026
Sulu
Detailed vulnerability description
The vulnerability allows a remote attacker to inject arbitrary HTML/JavaScript code.
The vulnerability exists due to cross-site scripting in the SuluMediaBundle MediaStreamController downloadAction method when processing the media download URL slug parameter. A remote attacker can send a specially crafted media download URL to inject arbitrary HTML/JavaScript code.
User interaction is required to trigger the reflected cross-site scripting issue.