Cross-site scripting in Sulu - CVE-2024-47618
Published: October 3, 2024 / Updated: May 12, 2026
Sulu
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script in a victim's browser.
The vulnerability exists due to cross-site scripting in the Media section when processing uploaded SVG files. A remote user can upload a crafted SVG file to execute arbitrary script in a victim's browser.
User interaction is required to access the uploaded SVG file, and the issue can affect other users including administrators.