sulu/sulu is vulnerable to SQL Injection
65
Medium Risk
The smart content query builder concatenates category, tag, and target-group identifiers directly into a JCR-SQL2 query string without integer casting or parameter binding. These identifiers can be influenced through public smart content filter parameters on the website, so untrusted input reaches the query unescaped. This allows the content query to be manipulated to return or disrupt content beyond the intended filter, without authentication. The fix casts these identifiers to integers before they are embedded in the query.
You are affected if you are using a version that falls within the vulnerable range and your site uses smart content with category, tag, or target-group filtering that is influenced by public request parameters.
sulu/sulu is vulnerable to SQL Injection in versions 1.6.0 - 2.6.24.
Upgrade the sulu/sulu library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant