CVE-2023-39343
Summary
| CVE | CVE-2023-39343 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-04 01:15:00 UTC |
| Updated | 2023-08-08 18:55:00 UTC |
| Description | Sulu is an open-source PHP content management system based on the Symfony framework. It allows over the Admin Login form to detect which user (username, email) exists and which one do not exist. Sulu Installation not using the old Symfony 5.4 security System and previous version are not impacted by this Security issue. The vulnerability has been patched in version 2.5.10. |
Risk And Classification
Problem Types: CWE-204
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Release Release 2.5.10 (2023-08-03) · sulu/sulu · GitHub | MISC | github.com | |
| Observable Response Discrepancy on Admin Login · Advisory · sulu/sulu · GitHub | MISC | github.com | |
| Merge pull request from GHSA-wmwf-49vv-p3mr · sulu/sulu@5f6c98b · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.