CVE-2024-27915
CVSS 3.1 Score 8.1 of 10 (high)
Details
Summary
CVE-2024-27915 is a vulnerability affecting the Sulu content management system. In versions 2.2.0 and prior to 2.4.17 and 2.5.13, role permissions for webspaces with security systems and permission checks enabled are bypassed, granting access to pages regardless of the intended restrictions. This issue does not affect webspaces without the security system. The vulnerability is addressed in versions 2.4.17 and 2.5.13, and applicants can apply a patch to `vendor/symfony/security-http/HttpUtils.php` or avoid installing certain Symfony security-http versions to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Sulu