Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2021-32737
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
XSS Injection in Media Collection Title was possible
Source: NVD (National Vulnerability Database)
Vulnerability Description
Sulu is an open-source PHP content management system based on the Symfony framework. In versions of Sulu prior to 1.6.41, it is possible for a logged in admin user to add a script injection (cross-site-scripting) in the collection title. The problem is patched in version 1.6.41. As a workaround, one may manually patch the affected JavaScript files in lieu of updating.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: NVD (National Vulnerability Database)
Vulnerability Title
SULU Sulu 跨站脚本漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
SULU Sulu是奥地利Sulu(SULU)公司的一款可扩展的、基于PHP的开源内容管理系统上的Symfony框架。 Sulu 中存在跨站脚本漏洞,该漏洞源于 collection title 未对用户输入数据做安全验证,攻击者在登陆admin账户后可通过输入恶意脚本来使受害者端代码执行。以下产品及版本受到影响:Sulu 1.6.41 之前版本。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
sulusulu < 1.6.41 -
II. Public POCs for CVE-2021-32737
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium
Qwen3.6-35B-A3B · 5031 chars
Paid plan includes:
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month
III. Intelligence Information for CVE-2021-32737
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2021-32737

No comments yet


Leave a comment