Sulu 是一个基于 Symfony 框架构建的开源 PHP 内容管理系统。在版本 2.6.25 和 3.0.8 之前,其预览链接端点(endpoint)及 中的 或 方法未对目标资源强制要求“查看(VIEW)”权限。 因此,任何已认证的后台管理员用户,只要知道目标资源的标识符,就可以为任意页面、文章或片段(snippet)创建或撤销预览链接,即使该内容位于该用户无权查看的 webspace 或 area 中。生成的预览 URL 是公开的,通过不透明令牌(opaque token)解析内容,使得该用户或任何收到链接
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82396 | 5.4 MEDIUM | Sulu: Stored XSS via media download inline-disposition override |
| CVE-2026-82395 | 5.3 MEDIUM | Sulu: Media move/update authorization bypass (IDOR) |
No comments yet