CVE-2026-92692: fallo de gravedad media en sulu
Sulu: JCR-SQL2 injection via `categories` query parameter (unauthenticated)
Publicada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 6.9epss 0.3%
probabilidad de explotación
0.3%top 75% de las CVE
explotación observada
noninguna fuente lo reporta
Sulu is an open-source PHP content management system based on the Symfony framework. Prior to 2.6.25 and 3.0.8, the affected Sulu 2.6 and 3.0 release lines have a Smart Content QueryBuilder in src/Sulu/Component/Content/SmartContent/QueryBuilder.php that concatenates category identifiers from the public categories query parameter into a JCR-SQL2 WHERE clause without numeric validation. On a public page containing a category-filtered Smart Content block, an unauthenticated attacker can alter query conditions to infer or enumerate content-repository nodes, including unpublished content, or submit malformed and expensive query fragments that degrade availability; this path does not modify repository data. This issue is fixed in versions 2.6.25 and 3.0.8.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
Productos afectados
sulu · suluCVEs relacionadas — sulu
En el mismo producto, de las más peligrosas a las menos.
CVE-2021-43836HIGHPHP file inclusion in the Sulu admin panelEPSS 2.0%CVE-2021-43835HIGHPrivilege escalation in the Sulu Admin panelEPSS 1.1%CVE-2020-15132MEDIUMReset Password / Login vulnerability in SuluEPSS 1.1%CVE-2021-32737HIGHXSS Injection in Media Collection Title was possibleEPSS 0.7%CVE-2023-39343MEDIUMSulu Observable Response Discrepancy on Admin LoginEPSS 0.6%CVE-2021-41169MEDIUMImproper Neutralization HTML tags in sulu/suluEPSS 0.6%