← Back

Suluformbundle

suluformbundle

Vendor: Sulu • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sulu
1Suluformbundle
Nov 21, 2024
Jun 6, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The SuluFormBundle adds support for creating dynamic forms in Sulu Admin. The TokenController get parameter formName is not sanitized in the returned input field which leads to XSS. This vulnerability is fixed in 2.5.3.