CVE-2024-27915

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Mar 6, 2024
Updated: Jan 8, 2025
CWE ID 863

Summary

CVE-2024-27915 is a vulnerability affecting the Sulu content management system. In versions 2.2.0 and prior to 2.4.17 and 2.5.13, role permissions for webspaces with security systems and permission checks enabled are bypassed, granting access to pages regardless of the intended restrictions. This issue does not affect webspaces without the security system. The vulnerability is addressed in versions 2.4.17 and 2.5.13, and applicants can apply a patch to `vendor/symfony/security-http/HttpUtils.php` or avoid installing certain Symfony security-http versions to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share