Sulu is an open-source PHP content management system based on the Symfony framework. Starting in versions 2.5.21, 2.6.5, and 3.0.0-alpha1, an admin user can upload SVG which may load external data via XML DOM library. This can be used for insecure XML External Entity References. The problem has been patched in versions 2.6.9, 2.5.25, and 3.0.0-alpha3. As a workaround, one may patch the effect file `src/Sulu/Bundle/MediaBundle/FileInspector/SvgFileInspector.php` manually.
Metrics
Affected Vendors & Products
References
History
Wed, 14 May 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 14 May 2025 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Sulu is an open-source PHP content management system based on the Symfony framework. Starting in versions 2.5.21, 2.6.5, and 3.0.0-alpha1, an admin user can upload SVG which may load external data via XML DOM library. This can be used for insecure XML External Entity References. The problem has been patched in versions 2.6.9, 2.5.25, and 3.0.0-alpha3. As a workaround, one may patch the effect file `src/Sulu/Bundle/MediaBundle/FileInspector/SvgFileInspector.php` manually. | |
Title | Sulu vulnerable to XXE in SVG File upload Inspector | |
Weaknesses | CWE-611 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-05-14T15:29:08.187Z
Updated: 2025-05-14T18:13:14.564Z
Reserved: 2025-05-09T19:49:35.620Z
Link: CVE-2025-47778

Updated: 2025-05-14T18:13:11.667Z

Status : Received
Published: 2025-05-14T16:15:29.110
Modified: 2025-05-14T16:15:29.110
Link: CVE-2025-47778

No data.