CVE-2024-37156 - CVE House
Back to Database
Status published Medium CVE-2024-37156

TokenController formName not sanitized in hidden input

Vulnerability Description

The SuluFormBundle adds support for creating dynamic forms in Sulu Admin. The TokenController get parameter formName is not sanitized in the returned input field which leads to XSS. This vulnerability is fixed in 2.5.3.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-37156

Credits & Attribution

No credits recorded in the NVD database.